Courseiva
Security →easyMultiple Choice

220-1102 Security Practice Question

A technician is configuring a Windows 11 workstation for a small business that handles credit card payments. The owner wants to ensure that stored cardholder data cannot be read if the drive is removed and attached to another computer. Which Windows feature should the technician enable?

⚠ Common exam trap

Many candidates confuse file-level encryption such as EFS with full-disk encryption such as BitLocker, which leads to choosing a partial solution that leaves most data exposed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

BitLocker

BitLocker encrypts the entire volume, so if the drive is removed and connected to another computer, the data remains unreadable without the recovery key or the original TPM. EFS, firewall rules, and UAC do not provide full-volume encryption, so they fail the physical-theft requirement. BitLocker is the correct built-in Windows feature for protecting data at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    BitLocker

    Why this is correct

    BitLocker provides full volume encryption for Windows 11, protecting data at rest so a removed drive cannot be read on another system. Enabling it on the OS drive with a TPM satisfies the requirement to render cardholder data unreadable if the disk is physically stolen. It is the built-in Windows feature that directly addresses this scenario.

  • ✗

    Encrypting File System (EFS)

    Why it's wrong here

    EFS encrypts individual files and folders for the user account that encrypted them. It does not protect the entire volume, and if the drive is removed, files not explicitly encrypted remain readable. It also depends on user certificates, which complicates recovery. EFS does not meet the requirement to protect all stored cardholder data at rest.

  • ✗

    Windows Defender Firewall

    Why it's wrong here

    Windows Defender Firewall filters network traffic to block unauthorized inbound and outbound connections. It has no capability to encrypt data stored on a disk, so removing the drive and attaching it elsewhere would still expose the cardholder data. This is a network control, not a data-at-rest protection mechanism.

  • ✗

    User Account Control (UAC)

    Why it's wrong here

    UAC prompts for elevation when administrative actions are attempted, helping prevent unauthorized system changes. It does not encrypt files or volumes, so physical removal of the drive would still allow an attacker to read the data. UAC addresses privilege escalation, not confidentiality of stored data.

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.