Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company wants to ensure that sensitive data on laptops is protected in case the laptop is lost or stolen. Which technology provides full-disk encryption for Windows 10?

⚠ Common exam trap

Many exam-takers confuse EFS (file-level encryption) with full-disk encryption, mistakenly thinking EFS provides the same level of protection as BitLocker, but EFS does not encrypt system files, the page file, or hibernation file, leaving residual data vulnerable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

BitLocker

BitLocker is the correct technology because it provides full-disk encryption (FDE) for Windows 10, encrypting the entire operating system volume and all data on the drive. It uses the AES encryption algorithm (typically 128-bit or 256-bit) and integrates with the Trusted Platform Module (TPM) to ensure the integrity of the boot process, protecting data even if the laptop is lost or stolen.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    BitLocker

    Why this is correct

    BitLocker Drive Encryption provides full-volume encryption by encrypting the entire Windows system and data drives with AES (Advanced Encryption Standard) using 128-bit or 256-bit keys, making data unreadable without the proper authentication. It can optionally integrate with a TPM to tie the encryption keys to the hardware, and it requires a recovery key or password for decryption when booting a compromised or different environment. BitLocker is available in Windows 10 Pro and Enterprise editions (not Home), and is the correct tool for ensuring that all sensitive data at rest is protected in case the laptop is lost or stolen.

  • ✗

    EFS

    Why it's wrong here

    EFS (Encrypting File System) is a user-level encryption feature that protects only individual files and folders selected by the user, typically via the file's Properties > Advanced settings. It relies on the user's profile certificate and does not encrypt the entire volume, leaving the operating system files, page files, temp files, and unselected data vulnerable. Because the scenario calls for protecting all sensitive data on the entire laptop drive against loss or theft, EFS is not a sufficient full-disk encryption solution.

  • ✗

    TPM

    Why it's wrong here

    TPM (Trusted Platform Module) is a hardware security chip that securely stores cryptographic keys, hashes, and certificates to attest to the platform's integrity. It is a foundation or enabler for BitLocker—allowing key sealing to hardware—but it does not perform any data encryption on its own. Without an encryption engine like BitLocker, the data on the drive remains in plaintext and is fully accessible if the drive is removed, so TPM alone cannot satisfy the requirement for protecting sensitive data.

  • ✗

    Secure Boot

    Why it's wrong here

    Secure Boot is a UEFI firmware feature that verifies the digital signature of the bootloader and other pre-boot components to ensure they are trusted and have not been tampered with, preventing unauthorized operating systems or rootkits from loading. It is a platform integrity mechanism that secures the boot process but does not encrypt any data on the disk. After the operating system boots, Secure Boot plays no role in protecting files, and even before boot it only checks signatures—it does not prevent someone from removing the hard drive and reading its contents directly, so it is not a data-at-rest encryption solution.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.