220-1102 exam dumps

220-1102 practice question 483 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 483

Single answerSecure/protect critical hardware (e.g., laptops)

A financial services company issues laptops to loan officers who frequently work in airports, hotels, and client sites. One laptop containing sensitive customer data was recently stolen from a car. Management asks a technician to recommend the BEST control to protect company data if another laptop is physically stolen, while still allowing employees to continue using the devices normally during travel. Which of the following should the technician implement?

  1. A

    Enable full-disk encryption such as BitLocker and require pre-boot authentication or TPM-based protection

  2. B

    Configure the screen to lock automatically after 15 minutes of inactivity

  3. C

    Install a privacy screen filter on each laptop display

  4. D

    Attach a cable lock to each laptop when employees are traveling

Show answer and explanation

Correct answer: A

Explanation

The key phrase in this scenario is protecting sensitive data if a laptop is physically stolen. For portable business systems, the most effective control is full-disk encryption, which protects data at rest and helps organizations meet common security and compliance expectations. Screen locks and privacy filters address different threats, such as unauthorized viewing or casual access while the device is unattended. Cable locks may reduce theft risk in some circumstances, but they do not ensure confidentiality of the stored data. This aligns with standard industry guidance, including Microsoft recommendations for BitLocker deployment on Windows business devices and general mobile-device security best practices that prioritize encryption for laptops containing sensitive information.

  • A. Correct.

    Correct. Full-disk encryption is the best control for protecting data at rest if a laptop is physically stolen. Technologies such as BitLocker are designed to prevent an unauthorized person from accessing the contents of the drive by removing it or booting the system another way. Using TPM-based protection, and where required by policy, pre-boot authentication, aligns with common enterprise best practices for safeguarding sensitive data on portable systems.

  • B. Incorrect.

    Incorrect. Automatic screen locking is an important security control for preventing unauthorized access when a user steps away from a device, but it does not adequately protect data if the entire laptop is stolen. An attacker may still be able to remove the drive or use offline attacks if the disk itself is not encrypted.

  • C. Incorrect.

    Incorrect. A privacy screen helps reduce visual shoulder surfing in public places such as airports or client offices. However, it does not protect data stored on the laptop after theft. This is a useful supplementary control, but it is not the best answer to the scenario's primary risk.

  • D. Incorrect.

    Incorrect. A cable lock can help deter opportunistic theft in fixed locations such as conference rooms or shared workspaces, but it is less practical during active travel and does not protect the data itself if the laptop is stolen anyway. Physical deterrence is valuable, but the question asks for the best control to protect company data after theft.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam