220-1102 Security Practice Question
A company wants to protect the data on its fleet of laptops. The security policy requires that if a laptop is stolen, the data on the internal hard drive must be unreadable even if the drive is removed and placed into another computer. Which technology, available on Windows 10 Pro, meets this requirement?
⚠ Common exam trap
It's easy for candidates to confuse file-level encryption (EFS) with full-disk encryption (BitLocker), assuming EFS protects the entire drive when it only protects individual files and is vulnerable to OS-level bypasses after drive removal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker Drive Encryption
BitLocker Drive Encryption is the correct answer because it provides full-disk encryption at the sector level, ensuring that all data on the internal hard drive is encrypted with AES (typically 128-bit or 256-bit). If the drive is removed and placed into another computer, the encrypted data remains unreadable without the recovery key or TPM authentication, directly meeting the policy requirement for stolen laptops.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
BitLocker Drive Encryption
Why this is correct
BitLocker Drive Encryption is the correct answer because it provides full-volume encryption using AES, rendering the entire OS and data partitions unreadable without the proper cryptographic key. When a BitLocker-protected drive is removed from its original system, the volume remains encrypted and inaccessible unless the recovery key or TPM-bound key is supplied, protecting data even against direct hard drive attacks. It integrates with the TPM to seal keys to the platform, and can also enforce pre-boot authentication via PIN or USB key for additional security.
- ✗
Encrypting File System (EFS)
Why it's wrong here
Encrypting File System (EFS) is wrong because it encrypts only individual files or folders on a per-user basis using the user's SID and a file encryption key, not the entire volume. The operating system and all unencrypted files remain readable, so the drive can still boot and most data can be accessed if the drive is removed. EFS provides confidentiality for specific sensitive files but does not offer the blanket protection needed for a lost or stolen laptop's entire storage.
- ✗
Secure Boot
Why it's wrong here
Secure Boot is wrong because it is a UEFI security feature that verifies the digital signature of the bootloader and kernel drivers against certificates stored in the firmware, preventing unauthorized code from loading during startup. It assumes the integrity of the boot process and blocks rootkits, but it encrypts no data at rest. If the drive is removed, Secure Boot has no effect, and all stored data remains plaintext and easily readable by another system.
- ✗
TPM (Trusted Platform Module)
Why it's wrong here
TPM (Trusted Platform Module) is wrong because it is a hardware security chip that generates, stores, and limits the use of cryptographic keys, and it is often used by BitLocker to store the encryption key sealed to the system's firmware state. However, a TPM by itself performs no encryption of user data; it only provides secure key management and attestation. Without BitLocker or another full-disk encryption tool, a TPM does nothing to protect the contents of the drive when it is removed.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Encryption Concepts for A+
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.