220-1102 exam dumps

220-1102 practice question 472 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 472

Single answerData-at-rest encryption

A company issues Windows 11 laptops to sales staff who frequently travel with customer contracts stored locally for offline access. One laptop was recently stolen from an employee's car while powered off. Management asks the technician to recommend the BEST control to reduce the risk of unauthorized access to files if another laptop is stolen in the future, while allowing authorized users to keep working normally. Which solution should the technician recommend?

  1. A

    Enable BitLocker drive encryption on the laptops and securely store recovery keys

  2. B

    Configure NTFS file permissions so only the assigned employee can open the files

  3. C

    Require users to connect through a VPN before they can sign in to Windows

  4. D

    Install antivirus software with real-time protection on all laptops

Show answer and explanation

Correct answer: A

Explanation

The key phrase in this scenario is that the laptop was stolen while powered off and management wants to protect files stored locally. That makes this a data-at-rest encryption problem, not a permissions, network, or malware problem. On Windows systems, BitLocker is the appropriate full-disk encryption technology to protect data on lost or stolen devices. Full-disk encryption is a widely accepted best practice for mobile endpoints because it protects the contents of the storage device even if an attacker removes the drive or attempts offline access. Microsoft documents BitLocker as a feature that helps protect data on lost, stolen, or inappropriately decommissioned devices, and recommends proper recovery key backup as part of deployment. For A+ Core 2, candidates should distinguish between data-at-rest protections such as BitLocker or FileVault and controls for data in transit such as VPNs, as well as understand that file permissions alone do not replace encryption.

  • A. Correct.

    Correct. BitLocker provides data-at-rest encryption for Windows devices by encrypting the drive so that data is unreadable if the device is stolen and the storage is accessed offline. This directly addresses the scenario of a powered-off stolen laptop. Securely storing recovery keys is a best practice so the organization can recover access if TPM, PIN, or hardware changes trigger recovery mode.

  • B. Incorrect.

    Incorrect. NTFS permissions control access within a running Windows session after the operating system has booted and authenticated a user. They do not protect data if someone removes the drive or boots the laptop using another operating system. This is a common misconception: file permissions are not the same as encryption for data at rest.

  • C. Incorrect.

    Incorrect. A VPN protects data in transit between a device and a remote network. It does not encrypt files stored on the laptop against offline access when the device is powered off or stolen. Someone might choose this because remote access security sounds related, but it does not solve the data-at-rest problem described.

  • D. Incorrect.

    Incorrect. Antivirus helps detect and block malware, but it does not prevent a thief from reading data directly from a stolen drive. This option improves endpoint security generally, but it does not specifically mitigate unauthorized access to locally stored files on a powered-off device.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam