220-1102 Question 230
Single answerFileVaultA company issues MacBook laptops to remote employees and requires full-disk encryption to protect data if a device is lost or stolen. One employee reports that after restarting the Mac, they must sign in before the startup disk unlocks, and the IT technician confirms FileVault is enabled. The user asks what FileVault is doing in this situation and why it is required. Which answer should the technician give?
- A
FileVault encrypts the startup disk and requires an authorized user or recovery key to unlock the disk at startup.
- B
FileVault scans files for malware before macOS loads, so the user must authenticate to start the antivirus engine.
- C
FileVault creates a bootable backup of the startup disk and requires a password to verify backup integrity during startup.
- D
FileVault synchronizes the user's desktop and documents to iCloud and requires sign-in so cloud files can mount before login.
Show answer and explanation
Correct answer: A
Explanation
This question tests practical understanding of FileVault in a real support scenario. FileVault is Apple's built-in full-disk encryption technology for macOS and is designed to protect data stored on the startup disk. When FileVault is enabled, the disk remains encrypted until an authorized user logs in at startup or the recovery key is used. This is why a user may see a login prompt before macOS fully loads. For A+ Core 2 purposes, candidates should recognize FileVault as a data-at-rest protection mechanism, not a malware tool, backup utility, or cloud-sync feature. Apple's platform security documentation and FileVault support documentation describe FileVault as full-disk encryption using XTS-AES encryption to help prevent unauthorized access to data on lost or stolen Macs.
- A. Correct.
Correct. FileVault is Apple's full-disk encryption feature for macOS. When enabled, it encrypts the contents of the startup disk and requires credentials from an authorized user account or the FileVault recovery key to unlock the disk during startup. This is the expected behavior and is specifically intended to protect data at rest if the Mac is lost or stolen.
- B. Incorrect.
Incorrect. Malware scanning is not the purpose of FileVault. macOS security features such as XProtect, Gatekeeper, and other endpoint protection tools address malware-related concerns, but FileVault specifically provides disk encryption rather than antivirus functionality.
- C. Incorrect.
Incorrect. FileVault does not create bootable backups. Backups on macOS are typically handled by Time Machine or other backup solutions. A user might choose this option because encryption and backup are both data-protection concepts, but they serve different purposes.
- D. Incorrect.
Incorrect. FileVault is unrelated to iCloud file synchronization. iCloud can sync user data such as Desktop and Documents if configured, but that feature does not explain pre-boot authentication for unlocking the startup disk. The startup unlock process is tied to disk encryption, not cloud storage.