Courseiva
Operating Systems →easyMultiple Choice

220-1102 Operating Systems Practice Question

A user needs to encrypt individual files and folders on a Windows 10 Pro workstation using a per-user certificate. Which built-in Windows feature should be used?

⚠ Common exam trap

Many candidates confuse BitLocker (full-disk encryption) with EFS (file-level encryption), failing to recognize that the question specifies 'individual files and folders' and 'per-user certificate,' which directly points to EFS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encrypting File System (EFS)

The Encrypting File System (EFS) is the built-in Windows feature that allows users to encrypt individual files and folders using a per-user certificate. EFS uses a symmetric file encryption key (FEK) that is protected by the user's public key, making the encryption transparent to the user and tied to their account. This matches the requirement for per-user certificate-based encryption of specific files and folders on a Windows 10 Pro workstation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    BitLocker

    Why it's wrong here

    BitLocker is a volume-level encryption tool that encrypts entire drives or partitions (e.g., the OS volume, fixed data drives, or removable drives) using AES. It does not provide per-file or per-folder encryption, and it does not tie access to files to individual user accounts via certificates; instead, it relies on TPM-based or startup-key protection at boot time. Because it operates at the volume level, it cannot selectively encrypt one user's file while leaving another file on the same volume unencrypted, making it incorrect for granular file/folder encryption.

  • ✓

    Encrypting File System (EFS)

    Why this is correct

    Encrypting File System (EFS) is the native Windows feature designed specifically for per-file and per-folder encryption. It uses an X.509 certificate tied to the user's account, and the encryption keys are stored in the user's profile, so only that authenticated user can decrypt the data. EFS operates transparently through the NTFS file system, allowing users to right-click a file or folder, enable encryption, and have the data automatically encrypted before being written to disk. This precise, certificate-based granularity is what makes EFS the correct answer for encrypting individual files and folders on Windows 10 Pro.

  • ✗

    Device Manager

    Why it's wrong here

    Device Manager is a Microsoft Management Console snap-in used for viewing and controlling hardware devices, updating drivers, enabling/disabling devices, and adjusting resource assignments (IRQs, I/O ports, memory ranges). It contains no cryptographic functions and cannot encrypt files, folders, or even whole volumes—it lacks any interface or service that could apply encryption to user data. Therefore, it is irrelevant to the task of encrypting individual files and folders.

  • ✗

    Disk Management

    Why it's wrong here

    Disk Management is a system utility that handles physical and logical storage administration, such as creating and deleting partitions, formatting volumes, assigning drive letters, and converting disk types (MBR to GPT). It does not perform any data encryption—it manages the layout and formatting of storage, not the security of individual files or folders. While a user could use Disk Management to format a partition with BitLocker or EFS support, the tool itself offers no built-in encryption capability for user data.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.