220-1102 Operating Systems Practice Question
A user is concerned about the security of sensitive files on their Windows 10 Pro laptop. They want to ensure that if the laptop is lost or stolen, the data on the hard drive cannot be accessed. Which built-in Windows feature should the technician enable to provide full disk encryption?
⚠ Common exam trap
Many exam-takers confuse EFS with full disk encryption, mistakenly believing that encrypting individual files provides the same level of protection as BitLocker, but EFS leaves critical system areas exposed and does not protect against offline attacks on the entire drive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker
BitLocker is the correct choice because it provides full disk encryption (FDE) for the entire Windows volume, including system files, page files, and hibernation files. When enabled, BitLocker uses AES encryption (typically 128-bit or 256-bit) to protect all data at rest, and if the laptop is lost or stolen, the drive cannot be accessed without the correct recovery key or TPM authentication. This meets the user's requirement for complete data protection in the event of theft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
BitLocker
Why this is correct
BitLocker is the correct choice because it provides full-volume AES encryption that protects all data on the drive, including the operating system, page files, and temp files. It leverages the TPM to securely bind encryption keys to the hardware, so if the laptop is lost or stolen the drive cannot be read without the proper key or recovery mechanism. This makes it the standard solution for whole-disk data-at-rest protection on Windows Pro and Enterprise editions.
- ✗
Encrypting File System (EFS)
Why it's wrong here
EFS encrypts only the individual files and folders chosen by the user, using a per-user certificate that is tied to the Windows account, not the entire volume. Because it operates at the file-system layer, system files, the pagefile, hibernation file, and other temporary data remain unprotected, allowing sensitive data remnants to leak. It also requires the user's account to be accessible, which is impractical for a lost laptop situation.
- ✗
Device Guard
Why it's wrong here
Device Guard is a virtualization-based security feature that enforces code integrity policies to ensure only trusted applications can run, protecting the kernel and system processes from malware. It does not perform any encryption and leaves all data on the hard drive readable if the physical disk or laptop is stolen. Its purpose is to control execution, not to protect confidentiality of files at rest.
- ✗
Credential Guard
Why it's wrong here
Credential Guard similarly uses virtualization-based security, but it isolates and protects user logon credentials such as NTLM password hashes inside a secure container to prevent pass-the-hash and credential theft attacks. It offers no file or disk encryption, so stolen storage can still be accessed by removing the drive. It is a security feature for authentication, not for protecting the confidentiality of sensitive files on a lost laptop.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Linux File System Structure
Key term
Data protection
Data protection refers to the practices and technologies used to safeguard personal and sensitive information from unauthorized access, loss, or corruption.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.