220-1102 exam dumps

220-1102 practice question 310 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 310

Single answer2.1 Summarize various security measures and their purposes.

A small accounting firm allows staff to use company-issued laptops both in the office and while traveling. After a recent theft from an employee's car, management wants to reduce the risk of exposing client financial records if a laptop is lost or stolen. They also want the solution to have minimal impact on how users access their files day to day. Which security measure should the technician recommend FIRST?

  1. A

    Enable full-disk encryption on all company laptops

  2. B

    Configure a host-based firewall to block inbound connections

  3. C

    Require users to change their passwords every 30 days

  4. D

    Install privacy screen filters on all laptop displays

Show answer and explanation

Correct answer: A

Explanation

The best first recommendation is full-disk encryption because the firm's main concern is preventing unauthorized access to sensitive client data if a laptop is lost or stolen. In A+ Core 2 security objectives, encryption is a primary control for protecting data at rest. This is a widely accepted best practice in enterprise environments, including guidance from Microsoft for BitLocker and Apple for FileVault, both of which are designed to protect information on lost devices with minimal day-to-day user impact after sign-in. The other options are valid security measures in other contexts: firewalls help with network protection, password policies help with account management, and privacy filters help with visual security. However, none of them is as directly effective as full-disk encryption for the specific risk in this scenario.

  • A. Correct.

    Correct. Full-disk encryption protects data at rest by making the contents of the drive unreadable without the proper authentication key or credentials. If a laptop is stolen, encryption significantly reduces the risk that client records can be accessed by someone who removes the drive or boots the device through other means. This directly addresses the stated concern while allowing users to continue working with their files normally after they authenticate.

  • B. Incorrect.

    Incorrect. A host-based firewall helps control network traffic to and from the laptop and is useful for reducing exposure to network-based attacks, especially on public or untrusted networks. However, it does not protect data stored on the laptop if the device is physically stolen.

  • C. Incorrect.

    Incorrect. More frequent password changes may affect account security policies, but by themselves they do not adequately protect data on a stolen laptop's storage media. An attacker could still access unencrypted data by removing the drive or using offline attack techniques. This is a common misconception because password policies protect authentication, not necessarily data at rest.

  • D. Incorrect.

    Incorrect. Privacy screen filters can reduce shoulder surfing and visual exposure in public places, which is helpful for confidentiality during use. However, they do not protect the contents of the drive if the laptop is lost or stolen. This option addresses a different physical security concern than the one described.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam