Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A technician needs to protect a laptop's data so that it is unreadable if the laptop is stolen. The laptop has a TPM 2.0 chip. Which technology should the technician use to encrypt the entire operating system drive?

⚠ Common exam trap

A common mix-up: candidates confuse EFS with full-disk encryption, not realizing EFS only encrypts at the file level and cannot protect the entire OS drive, especially when a TPM is available for BitLocker.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

BitLocker Drive Encryption

BitLocker Drive Encryption is the correct technology because it uses the TPM 2.0 chip to securely store encryption keys and provides full-volume encryption of the operating system drive, rendering data unreadable if the laptop is stolen. It integrates with Windows and supports pre-boot authentication, ensuring the drive remains encrypted even if the device is physically removed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EFS (Encrypting File System)

    Why it's wrong here

    EFS (Encrypting File System) encrypts only individual files and folders on an NTFS volume, not the entire drive. Its decryption keys are tied to the user's Windows account and are not protected by the TPM, so other data, system files, and the page file remain unencrypted. If an attacker removes the laptop's drive, they can still access all non-EFS-encrypted content, making EFS insufficient for whole-drive confidentiality.

  • ✓

    BitLocker Drive Encryption

    Why this is correct

    BitLocker Drive Encryption performs full-volume encryption, protecting the entire Windows partition, including system, hibernation, and temporary files. It uses the TPM to store and seal the encryption keys, verifying system integrity at boot; if the drive is removed or the hardware altered, the data remains inaccessible. This makes it the correct choice for ensuring an entire laptop's data is unreadable when the device is lost or stolen.

  • ✗

    Secure Boot

    Why it's wrong here

    Secure Boot is a UEFI-based feature that validates the digital signature of the boot loader and kernel before execution to prevent malicious firmware and rootkits from taking control of the startup process. It does not implement any form of data encryption or protect files at rest; a drive removed from the laptop can still be read on another machine. Its purpose is system integrity, not data confidentiality.

  • ✗

    Windows Defender Antivirus

    Why it's wrong here

    Windows Defender Antivirus provides real-time scanning, detection, and removal of malware, including viruses, ransomware, and spyware. It does not encrypt storage and has no mechanism to render data unreadable if the device is stolen or the disk is physically accessed. Antivirus tools protect the system from running malicious code, but they cannot keep stored data confidential.

Go deeper

Related to this question

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.