Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

An organization requires full disk encryption on all laptops. One laptop does not have a TPM chip installed. Which method can still be used to encrypt the entire hard drive on Windows 10 Pro?

⚠ Common exam trap

Candidates often confuse EFS with full disk encryption or assume BitLocker absolutely requires a TPM, overlooking the Group Policy exception that allows a USB startup key as a valid alternative.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use BitLocker with a startup key on a USB flash drive

BitLocker can operate without a TPM by using a startup key stored on a USB flash drive. When the system boots, the user must insert the USB drive to provide the key, which decrypts the volume master key and allows the OS to load. This is configured via Group Policy or the `manage-bde` command with the `-tpm` and `-startupkey` options.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use BitLocker with a startup key on a USB flash drive

    Why this is correct

    BitLocker with a startup key is a recognized full-disk encryption solution that can operate without a TPM chip. The USB flash drive holds an encrypted key, which must be inserted during the boot process to unlock the drive. This configuration is ideal for laptops that lack TPM 2.0 but still need to meet data-at-rest encryption requirements.

  • ✗

    Use Encrypting File System (EFS)

    Why it's wrong here

    EFS (Encrypting File System) encrypts chosen files and folders at the NTFS level, not the entire volume. It does not encrypt system files, the pagefile, or the operating system itself, leaving sensitive remnants on the hard disk. Since the requirement mandates full disk encryption, EFS provides only selective, user-level protection and therefore fails the compliance objective.

  • ✗

    Use Microsoft BitLocker Administration and Monitoring (MBAM)

    Why it's wrong here

    MBAM is a centralized administration platform for managing BitLocker lifecycle operations across an enterprise, such as policy deployment, key recovery, and compliance reporting. It does not perform any encryption on its own; it simply orchestrates and reports on BitLocker settings on client workstations. Choosing MBAM alone would leave laptops completely unencrypted, because encryption must still be enabled via BitLocker.

  • ✗

    Use Windows Defender System Guard

    Why it's wrong here

    Windows Defender System Guard is a hardware-backed integrity feature that protects the boot path and system firmware through Secure Boot and Virtualization-Based Security. It depends on TPM for attestation and credential isolation, but none of its capabilities include encrypting user data or the system disk. Thus, it cannot satisfy a full disk encryption requirement, even though it strengthens the overall trustworthiness of an encrypted device.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization requires that all laptops have full-disk encryption to protect data in case of theft. Which Windows 10 feature should be used to meet this requirement?

easy
  • A.Encrypting File System (EFS)
  • ✓ B.BitLocker Drive Encryption
  • C.NTFS permissions
  • D.Windows Defender

Why B: BitLocker Drive Encryption is the correct Windows 10 feature for full-disk encryption because it encrypts the entire volume, including system files, hibernation files, and page files, using AES encryption algorithms (128-bit or 256-bit). This ensures that if a laptop is stolen, the data remains inaccessible without the recovery key or TPM authentication, meeting the organization's requirement for data protection at rest.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.