220-1102 Security Practice Question
A technician needs to ensure that a laptop's data is protected in case the laptop is stolen. The laptop has a TPM 2.0 chip and runs Windows 10 Pro. Which Windows feature should be configured to provide full-disk encryption?
⚠ Common exam trap
Many exam-takers confuse EFS (file-level encryption) with BitLocker (full-disk encryption), assuming any encryption feature will suffice, but the question specifically requires full-disk encryption with TPM support.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker Drive Encryption
BitLocker Drive Encryption is the correct answer because it provides full-disk encryption that integrates with the TPM 2.0 chip to protect data at rest. When the laptop is stolen, BitLocker encrypts the entire drive, requiring the TPM to release the decryption key during boot, preventing unauthorized access to the data. Windows 10 Pro includes BitLocker, making it the appropriate feature for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypting File System (EFS)
Why it's wrong here
EFS (Encrypting File System) is a Windows NTFS feature that encrypts individual files or folders on a per-user basis, using a file encryption key (FEK) derived from the user's password. It does not encrypt the entire system volume, leaving critical metadata, Pagefile.sys, hiberfil.sys, and the OS kernel unencrypted and accessible. Because it relies on the user's Windows credentials rather than a TPM, it provides no protection against an attacker who boots from a separate OS or extracts the drive. Therefore, EFS is unsuitable for full-device data protection in a laptop theft scenario.
- ✓
BitLocker Drive Encryption
Why this is correct
BitLocker Drive Encryption is a full-volume encryption feature built into Windows 10 Pro and Enterprise that encrypts the entire Windows system volume, including user files, system files, the pagefile, and hibernation files. It uses the TPM to securely store the full-volume encryption key and can be configured with a PIN or USB startup key for pre-boot authentication, ensuring that an attacker cannot decrypt the drive by simply removing the hard disk. This makes BitLocker the correct and standard solution for protecting a laptop's data at rest if the device is physically stolen.
- ✗
Windows Defender Firewall
Why it's wrong here
Windows Defender Firewall is a host-based network firewall that filters inbound and outbound traffic based on IP addresses, ports, and application rules. It operates at the network layer and is designed to block unauthorized network connections, not to encrypt or secure data stored on the local hard drive. If a laptop is physically stolen, the firewall becomes irrelevant because the attacker can bypass it entirely by removing the storage drive or booting from an external medium. Thus, it does nothing to prevent the thief from reading the data at rest.
- ✗
Secure Boot
Why it's wrong here
Secure Boot is a UEFI firmware security feature that verifies the digital signature of boot loaders and kernel drivers against certificates stored in the UEFI database, preventing unsigned or malicious code from executing during the boot process. While it protects against bootkits and rootkits, it does not encrypt any data on the hard drive. The contents of the drive remain in plaintext, so an attacker who physically removes the drive and connects it to another computer can still read all unprotected files. Therefore, Secure Boot is a boot integrity control, not a data-at-rest encryption mechanism.
Visual reference
Go deeper
Related to this question
Learn chapter
TPM and Secure Boot
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
BitLocker
BitLocker is a full-disk encryption feature built into Windows that protects data by encrypting the entire drive so that unauthorized users cannot access files without the correct recovery key.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.