220-1102 Operating Systems Practice Question
A user needs to encrypt individual files and folders on a Windows 10 Pro workstation using a per-user certificate. Which built-in Windows feature should be used?
⚠ Common exam trap
Many candidates confuse BitLocker (full-disk encryption) with EFS (file-level encryption), failing to recognize that the question specifies 'individual files and folders' and 'per-user certificate,' which directly points to EFS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Encrypting File System (EFS)
The Encrypting File System (EFS) is the built-in Windows feature that allows users to encrypt individual files and folders using a per-user certificate. EFS uses a symmetric file encryption key (FEK) that is protected by the user's public key, making the encryption transparent to the user and tied to their account. This matches the requirement for per-user certificate-based encryption of specific files and folders on a Windows 10 Pro workstation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
BitLocker
Why it's wrong here
BitLocker is a volume-level encryption tool that encrypts entire drives or partitions (e.g., the OS volume, fixed data drives, or removable drives) using AES. It does not provide per-file or per-folder encryption, and it does not tie access to files to individual user accounts via certificates; instead, it relies on TPM-based or startup-key protection at boot time. Because it operates at the volume level, it cannot selectively encrypt one user's file while leaving another file on the same volume unencrypted, making it incorrect for granular file/folder encryption.
- ✓
Encrypting File System (EFS)
Why this is correct
Encrypting File System (EFS) is the native Windows feature designed specifically for per-file and per-folder encryption. It uses an X.509 certificate tied to the user's account, and the encryption keys are stored in the user's profile, so only that authenticated user can decrypt the data. EFS operates transparently through the NTFS file system, allowing users to right-click a file or folder, enable encryption, and have the data automatically encrypted before being written to disk. This precise, certificate-based granularity is what makes EFS the correct answer for encrypting individual files and folders on Windows 10 Pro.
- ✗
Device Manager
Why it's wrong here
Device Manager is a Microsoft Management Console snap-in used for viewing and controlling hardware devices, updating drivers, enabling/disabling devices, and adjusting resource assignments (IRQs, I/O ports, memory ranges). It contains no cryptographic functions and cannot encrypt files, folders, or even whole volumes—it lacks any interface or service that could apply encryption to user data. Therefore, it is irrelevant to the task of encrypting individual files and folders.
- ✗
Disk Management
Why it's wrong here
Disk Management is a system utility that handles physical and logical storage administration, such as creating and deleting partitions, formatting volumes, assigning drive letters, and converting disk types (MBR to GPT). It does not perform any data encryption—it manages the layout and formatting of storage, not the security of individual files or folders. While a user could use Disk Management to format a partition with BitLocker or EFS support, the tool itself offers no built-in encryption capability for user data.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
User Account Control (UAC)
Key term
Encrypting File System
The Encrypting File System (EFS) is a Windows feature that encrypts individual files and folders on an NTFS volume so that only authorized users can read them.
Key term
New Technology File System
New Technology File System (NTFS) is a modern file system developed by Microsoft that controls how data is stored, organized, and accessed on Windows-based hard drives and other storage devices.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.