Courseiva
Operating Systems →easyMultiple Choice

220-1102 Operating Systems Practice Question

A user is concerned about the security of sensitive files on their Windows 10 Pro laptop. They want to ensure that if the laptop is lost or stolen, the data on the hard drive cannot be accessed. Which built-in Windows feature should the technician enable to provide full disk encryption?

⚠ Common exam trap

Many exam-takers confuse EFS with full disk encryption, mistakenly believing that encrypting individual files provides the same level of protection as BitLocker, but EFS leaves critical system areas exposed and does not protect against offline attacks on the entire drive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

BitLocker

BitLocker is the correct choice because it provides full disk encryption (FDE) for the entire Windows volume, including system files, page files, and hibernation files. When enabled, BitLocker uses AES encryption (typically 128-bit or 256-bit) to protect all data at rest, and if the laptop is lost or stolen, the drive cannot be accessed without the correct recovery key or TPM authentication. This meets the user's requirement for complete data protection in the event of theft.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    BitLocker

    Why this is correct

    BitLocker is the correct choice because it provides full-volume AES encryption that protects all data on the drive, including the operating system, page files, and temp files. It leverages the TPM to securely bind encryption keys to the hardware, so if the laptop is lost or stolen the drive cannot be read without the proper key or recovery mechanism. This makes it the standard solution for whole-disk data-at-rest protection on Windows Pro and Enterprise editions.

  • ✗

    Encrypting File System (EFS)

    Why it's wrong here

    EFS encrypts only the individual files and folders chosen by the user, using a per-user certificate that is tied to the Windows account, not the entire volume. Because it operates at the file-system layer, system files, the pagefile, hibernation file, and other temporary data remain unprotected, allowing sensitive data remnants to leak. It also requires the user's account to be accessible, which is impractical for a lost laptop situation.

  • ✗

    Device Guard

    Why it's wrong here

    Device Guard is a virtualization-based security feature that enforces code integrity policies to ensure only trusted applications can run, protecting the kernel and system processes from malware. It does not perform any encryption and leaves all data on the hard drive readable if the physical disk or laptop is stolen. Its purpose is to control execution, not to protect confidentiality of files at rest.

  • ✗

    Credential Guard

    Why it's wrong here

    Credential Guard similarly uses virtualization-based security, but it isolates and protects user logon credentials such as NTLM password hashes inside a secure container to prevent pass-the-hash and credential theft attacks. It offers no file or disk encryption, so stolen storage can still be accessed by removing the drive. It is a security feature for authentication, not for protecting the confidentiality of sensitive files on a lost laptop.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.