220-1102 exam dumps

220-1102 practice question 382 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 382

Single answerBitLocker-To-Go

A company issues encrypted USB flash drives to field technicians so customer data remains protected if a drive is lost. A technician uses a Windows 11 Pro laptop and reports that a new company USB drive is not encrypted yet. You need to configure the removable drive so it requires a password before files can be accessed on other supported Windows systems. Which action should you take?

  1. A

    Open BitLocker Drive Encryption, turn on BitLocker for the removable drive, and choose to unlock the drive with a password

  2. B

    Open EFS settings on the USB drive and encrypt the entire removable disk so any computer will require the technician's Windows sign-in

  3. C

    Use Device Manager to enable drive-level hardware encryption and set a BIOS password for the USB device

  4. D

    Convert the USB drive to NTFS, then enable Secure Boot so the drive stays encrypted when connected to another PC

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use BitLocker To Go, which is specifically designed for encrypting removable data drives such as USB flash drives. In a real-world A+ Core 2 scenario, a technician would enable BitLocker on the removable drive and choose an appropriate unlock method, commonly a password for cross-system usability on supported Windows editions. This aligns with Microsoft best practices for protecting data at rest on portable media. EFS is file-based and user-certificate-based rather than the standard full removable-drive protection method. BIOS passwords and Secure Boot are valuable controls in other contexts, but they do not replace removable-drive encryption. For exam purposes, remember that BitLocker protects fixed drives, while BitLocker To Go is the removable-drive implementation.

  • A. Correct.

    Correct. BitLocker To Go is the Windows feature used to encrypt removable data drives such as USB flash drives. On supported editions of Windows, you enable BitLocker for the removable drive and select a password-based unlock method. This is the practical way to protect data on a USB drive so that if it is lost, the contents remain encrypted and require authentication to open.

  • B. Incorrect.

    Incorrect. Encrypting File System (EFS) encrypts files and folders, not the entire removable drive in the same way BitLocker To Go does. EFS is tied to user certificates and is not the standard solution for securing portable USB media for broad business use. It also does not make the drive require the user's normal Windows sign-in on other computers.

  • C. Incorrect.

    Incorrect. Device Manager does not provide a standard method to configure BitLocker-style encryption for a USB drive, and a BIOS password protects system firmware access, not the contents of a removable flash drive. This option mixes unrelated security controls, which is a common misconception.

  • D. Incorrect.

    Incorrect. While BitLocker can work with NTFS and other supported file systems depending on the scenario, converting the drive to NTFS and enabling Secure Boot does not by itself encrypt a USB flash drive. Secure Boot protects the system boot process, not removable-drive data confidentiality.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam