220-1102 Security Practice Question
A technician is configuring a Windows 11 workstation for a small business that handles credit card payments. The owner wants to ensure that stored cardholder data cannot be read if the drive is removed and attached to another computer. Which Windows feature should the technician enable?
⚠ Common exam trap
Many candidates confuse file-level encryption such as EFS with full-disk encryption such as BitLocker, which leads to choosing a partial solution that leaves most data exposed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker
BitLocker encrypts the entire volume, so if the drive is removed and connected to another computer, the data remains unreadable without the recovery key or the original TPM. EFS, firewall rules, and UAC do not provide full-volume encryption, so they fail the physical-theft requirement. BitLocker is the correct built-in Windows feature for protecting data at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
BitLocker
Why this is correct
BitLocker provides full volume encryption for Windows 11, protecting data at rest so a removed drive cannot be read on another system. Enabling it on the OS drive with a TPM satisfies the requirement to render cardholder data unreadable if the disk is physically stolen. It is the built-in Windows feature that directly addresses this scenario.
- ✗
Encrypting File System (EFS)
Why it's wrong here
EFS encrypts individual files and folders for the user account that encrypted them. It does not protect the entire volume, and if the drive is removed, files not explicitly encrypted remain readable. It also depends on user certificates, which complicates recovery. EFS does not meet the requirement to protect all stored cardholder data at rest.
- ✗
Windows Defender Firewall
Why it's wrong here
Windows Defender Firewall filters network traffic to block unauthorized inbound and outbound connections. It has no capability to encrypt data stored on a disk, so removing the drive and attaching it elsewhere would still expose the cardholder data. This is a network control, not a data-at-rest protection mechanism.
- ✗
User Account Control (UAC)
Why it's wrong here
UAC prompts for elevation when administrative actions are attempted, helping prevent unauthorized system changes. It does not encrypt files or volumes, so physical removal of the drive would still allow an attacker to read the data. UAC addresses privilege escalation, not confidentiality of stored data.
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
Key term
UAC
User Account Control is a Windows security feature that prevents unauthorized changes to your computer by asking for permission before allowing certain actions.
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.