Courseiva
easyMultiple ChoiceObjective-mapped

220-1102 Practice Question: A user wants to encrypt a USB flash drive so that…

A user wants to encrypt a USB flash drive so that if it is lost, the data cannot be read on another computer. The USB drive will be used on both Windows 10 and Windows 11 devices. Which Windows feature should be used?

⚠ Common exam trap

CompTIA often tests the distinction between EFS and BitLocker To Go, where candidates mistakenly choose EFS because they think file-level encryption is sufficient for removable media, but EFS does not protect data when the drive is moved to another computer because the encryption certificate is not present on the target system.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

BitLocker To Go

BitLocker To Go is the correct choice because it provides full-disk encryption specifically designed for removable drives like USB flash drives. It encrypts the entire drive using AES encryption, and when the drive is inserted into another Windows 10 or Windows 11 computer, the user must enter the password or use a smart card/recovery key to access the data. This ensures that if the drive is lost, the data remains unreadable on any other system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • EFS (Encrypting File System)

    Why it's wrong here

    EFS (Encrypting File System) is a feature of Windows that allows for the encryption of individual files and folders on an NTFS-formatted volume. While it provides data protection, it is not designed for encrypting entire removable drives like a USB flash drive. Furthermore, EFS encryption is tied to the user's certificate on the specific system where the encryption occurred, making it impractical for portable use across different computers without careful certificate management.

  • BitLocker To Go

    Why this is correct

    BitLocker To Go is the dedicated feature within Windows Pro and Enterprise editions specifically designed for encrypting removable data drives, such as USB flash drives and external hard drives. It provides full-disk encryption, protecting all data stored on the drive with a password or smart card. This feature ensures data security even if the drive is lost or stolen, and it allows access to the encrypted content on other Windows 10/11 systems with the correct credentials.

  • Windows Defender Encryption

    Why it's wrong here

    Windows Defender, now known as Microsoft Defender Antivirus, is primarily a security suite focused on real-time protection against viruses, malware, and other threats. It provides antivirus scanning, firewall capabilities, and exploit protection. However, there is no built-in feature called "Windows Defender Encryption" that provides data encryption for files, folders, or entire drives, making it an incorrect option for encrypting a USB flash drive.

  • Secure Boot

    Why it's wrong here

    Secure Boot is a security feature integrated into the UEFI (Unified Extensible Firmware Interface) firmware of a computer, designed to prevent malicious software from loading during the system startup process. It ensures that only digitally signed and trusted operating system boot loaders and drivers are allowed to execute. Secure Boot's function is to protect the integrity of the boot path, not to encrypt data on storage devices like a USB flash drive.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

Go deeper

Related to this question

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.