220-1102 Security Practice Question
A company wants to ensure that sensitive data on laptops is protected in case the laptop is lost or stolen. Which technology provides full-disk encryption for Windows 10?
⚠ Common exam trap
Many exam-takers confuse EFS (file-level encryption) with full-disk encryption, mistakenly thinking EFS provides the same level of protection as BitLocker, but EFS does not encrypt system files, the page file, or hibernation file, leaving residual data vulnerable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker
BitLocker is the correct technology because it provides full-disk encryption (FDE) for Windows 10, encrypting the entire operating system volume and all data on the drive. It uses the AES encryption algorithm (typically 128-bit or 256-bit) and integrates with the Trusted Platform Module (TPM) to ensure the integrity of the boot process, protecting data even if the laptop is lost or stolen.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
BitLocker
Why this is correct
BitLocker Drive Encryption provides full-volume encryption by encrypting the entire Windows system and data drives with AES (Advanced Encryption Standard) using 128-bit or 256-bit keys, making data unreadable without the proper authentication. It can optionally integrate with a TPM to tie the encryption keys to the hardware, and it requires a recovery key or password for decryption when booting a compromised or different environment. BitLocker is available in Windows 10 Pro and Enterprise editions (not Home), and is the correct tool for ensuring that all sensitive data at rest is protected in case the laptop is lost or stolen.
- ✗
EFS
Why it's wrong here
EFS (Encrypting File System) is a user-level encryption feature that protects only individual files and folders selected by the user, typically via the file's Properties > Advanced settings. It relies on the user's profile certificate and does not encrypt the entire volume, leaving the operating system files, page files, temp files, and unselected data vulnerable. Because the scenario calls for protecting all sensitive data on the entire laptop drive against loss or theft, EFS is not a sufficient full-disk encryption solution.
- ✗
TPM
Why it's wrong here
TPM (Trusted Platform Module) is a hardware security chip that securely stores cryptographic keys, hashes, and certificates to attest to the platform's integrity. It is a foundation or enabler for BitLocker—allowing key sealing to hardware—but it does not perform any data encryption on its own. Without an encryption engine like BitLocker, the data on the drive remains in plaintext and is fully accessible if the drive is removed, so TPM alone cannot satisfy the requirement for protecting sensitive data.
- ✗
Secure Boot
Why it's wrong here
Secure Boot is a UEFI firmware feature that verifies the digital signature of the bootloader and other pre-boot components to ensure they are trusted and have not been tampered with, preventing unauthorized operating systems or rootkits from loading. It is a platform integrity mechanism that secures the boot process but does not encrypt any data on the disk. After the operating system boots, Secure Boot plays no role in protecting files, and even before boot it only checks signatures—it does not prevent someone from removing the hard drive and reading its contents directly, so it is not a data-at-rest encryption solution.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Operating system
An operating system (OS) is the core software that manages a computer's hardware and software resources, providing common services for computer programs.
Key term
TPM
TPM (Trusted Platform Module) is a dedicated hardware chip on a computer's motherboard that stores cryptographic keys, passwords, and certificates to secure the system against unauthorized access and tampering.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.