Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

Which encryption standard is used by BitLocker To Go to protect data on removable drives such as USB flash drives?

⚠ Common exam trap

Candidates often confuse encryption standards (AES) with hashing algorithms (SHA) or asymmetric ciphers (RSA), mistakenly thinking BitLocker uses RSA for the actual data encryption or SHA for encrypting the drive contents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AES

BitLocker To Go uses AES (Advanced Encryption Standard) with 128-bit or 256-bit keys to encrypt data on removable drives. AES is the symmetric encryption standard mandated by the U.S. government for protecting classified information and is the default cipher for BitLocker. This ensures that data on USB flash drives is encrypted at rest and requires a password or smart card for access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DES

    Why it's wrong here

    The Data Encryption Standard (DES) is a symmetric block cipher with an effective key size of only 56 bits, making it vulnerable to brute-force attacks. It was deprecated decades ago and is not implemented in BitLocker's encryption engine. BitLocker To Go, like all BitLocker volumes, relies on AES for confidentiality, never DES.

  • ✓

    AES

    Why this is correct

    AES (Advanced Encryption Standard) is the symmetric encryption algorithm used by BitLocker and BitLocker To Go to encrypt data at rest. It supports 128-bit and 256-bit keys, and modern BitLocker deployments typically use XTS-AES, which provides strong protection against manipulation. This makes AES the correct answer for the cipher that secures removable drives.

  • ✗

    RSA

    Why it's wrong here

    RSA is an asymmetric (public-key) algorithm used for encrypting keys, signatures, or other small payloads, not for bulk disk encryption. BitLocker may use RSA for certificate-based recovery keys or to wrap key protectors, but the actual volume data is encrypted with AES. Its mathematical overhead makes RSA unsuitable for full-disk encryption.

  • ✗

    SHA

    Why it's wrong here

    SHA (Secure Hash Algorithm) is a family of cryptographic hash functions, such as SHA-256, used for integrity verification and digital signatures, not for encryption. BitLocker uses SHA for various integrity checks (like validating the TPM state), but data confidentiality is achieved with AES. Hashing is one-way, so it cannot be used to encrypt a disk for later decryption.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

Go deeper

Related to this question

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.