SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company issues laptops to all employees with BitLocker full-disk encryption enabled. If a laptop is stolen, the data on the hard drive cannot be read without the recovery key. Which security principle does this measure primarily protect?
⚠ Common exam trap
Many candidates confuse encryption's role in confidentiality with integrity or availability, as candidates may mistakenly think encryption prevents data modification (integrity) or ensures access (availability), but it strictly prevents unauthorized reading.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confidentiality
BitLocker full-disk encryption ensures that data on a stolen laptop's hard drive is unreadable without the recovery key, directly protecting against unauthorized access. This aligns with the confidentiality principle, which safeguards sensitive information from disclosure to unauthorized parties.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Integrity
Why it's wrong here
While BitLocker encrypts data, its primary function is not to guarantee data integrity. Integrity services, such as digital signatures or cryptographic hashing (e.g., HMAC), are designed to detect unauthorized alteration or tampering of data. BitLocker prevents unauthorized reading of data, but it does not inherently prevent an attacker with physical access from modifying the encrypted data, which would likely corrupt it but not be detected as a breach of integrity by BitLocker itself.
When this WOULD be correct
A question about ensuring that data has not been modified during transmission or storage, such as using hashing or digital signatures to detect tampering, would have integrity as the correct answer.
- ✗
Availability
Why it's wrong here
Availability ensures that authorized users can access systems and data when required. BitLocker encryption does not inherently enhance availability; in fact, it introduces a dependency on the decryption key. If the recovery key is lost, corrupted, or inaccessible, the encrypted data becomes permanently unavailable, directly hindering access. While BitLocker aims to protect data, it does not provide mechanisms to ensure the continuous uptime or accessibility of the system or its data.
When this WOULD be correct
A question about implementing RAID 1 (mirroring) or backup systems to ensure data remains accessible after a hard drive failure would have availability as the correct answer.
- ✓
Confidentiality
Why this is correct
BitLocker full disk encryption directly addresses confidentiality by transforming data into an unreadable format, making it inaccessible to anyone without the correct decryption key. This mechanism prevents unauthorized disclosure of sensitive information stored on the laptop, even if the device is lost or stolen. By requiring authentication (e.g., TPM, PIN, USB key) to unlock the drive, BitLocker ensures that only authorized users or systems can access the plaintext data, thereby safeguarding its secrecy.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation provides irrefutable proof that a specific action or transaction occurred and originated from a particular source, preventing denial by the sender or recipient. BitLocker's full disk encryption secures data at rest but does not provide any mechanism to link a user's actions (e.g., creating a file, sending an email) to their identity in a way that prevents them from later denying those actions. This function is typically achieved through digital signatures or robust logging and auditing systems, not data encryption.
When this WOULD be correct
A question that asks: 'A company uses digital signatures on all emails to ensure that senders cannot deny having sent them. Which security principle does this primarily protect?' would make non-repudiation the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓ConfidentialityCorrect answer▾
Why this is correct
BitLocker full disk encryption directly addresses confidentiality by transforming data into an unreadable format, making it inaccessible to anyone without the correct decryption key. This mechanism prevents unauthorized disclosure of sensitive information stored on the laptop, even if the device is lost or stolen. By requiring authentication (e.g., TPM, PIN, USB key) to unlock the drive, BitLocker ensures that only authorized users or systems can access the plaintext data, thereby safeguarding its secrecy.
✗IntegrityWrong answer — click to see why▾
Why this is wrong here
BitLocker encryption prevents unauthorized reading of data, which protects confidentiality, not integrity. Integrity ensures data is not tampered with, which is not the primary concern here.
★ When this WOULD be the correct answer
A question about ensuring that data has not been modified during transmission or storage, such as using hashing or digital signatures to detect tampering, would have integrity as the correct answer.
Why candidates choose this
Candidates may confuse encryption with integrity because both involve data protection, but encryption primarily addresses unauthorized access (confidentiality), not unauthorized modification.
✗AvailabilityWrong answer — click to see why▾
Why this is wrong here
BitLocker encryption prevents unauthorized reading of data, which protects confidentiality, not availability. Availability ensures systems are accessible when needed, which encryption does not directly address.
★ When this WOULD be the correct answer
A question about implementing RAID 1 (mirroring) or backup systems to ensure data remains accessible after a hard drive failure would have availability as the correct answer.
Why candidates choose this
Candidates may confuse encryption with protecting data from loss (e.g., theft causing data unavailability), but encryption primarily prevents unauthorized access, not loss of access.
✗Non-repudiationWrong answer — click to see why▾
Why this is wrong here
Non-repudiation ensures that an action or event cannot be denied by the involved parties, typically through digital signatures or audit logs. BitLocker encryption does not provide proof of who accessed data or performed actions; it only prevents unauthorized reading of data, which is a confidentiality measure.
★ When this WOULD be the correct answer
A question that asks: 'A company uses digital signatures on all emails to ensure that senders cannot deny having sent them. Which security principle does this primarily protect?' would make non-repudiation the correct answer.
Why candidates choose this
Candidates may confuse encryption with non-repudiation because both involve cryptographic mechanisms, but encryption protects data at rest (confidentiality) while non-repudiation deals with accountability and proof of origin or action.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Confidentiality
Confidentiality means keeping sensitive information secret and accessible only to authorized people or systems.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.