220-1102 exam dumps

220-1102 practice question 55 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 55

Single answerPro

A technician is preparing several company-owned Windows 11 Pro laptops for remote employees who will work with sensitive customer data. Management wants a security feature that helps protect data if a laptop is lost or stolen, but they do not want to rely on a separate third-party encryption product. Which Windows 11 Pro feature should the technician configure to best meet this requirement?

  1. A

    BitLocker Drive Encryption

  2. B

    Microsoft Defender Firewall

  3. C

    User Account Control (UAC)

  4. D

    Encrypting File System (EFS)

Show answer and explanation

Correct answer: A

Explanation

The best answer is BitLocker Drive Encryption because the scenario focuses on protecting sensitive data on Windows 11 Pro laptops in the event of loss or theft. In A+ Core 2, candidates are expected to distinguish between security features that protect stored data and those that manage accounts, permissions, or network traffic. BitLocker is designed for full-volume encryption and is a standard best practice for mobile business devices. By contrast, Defender Firewall protects network communications, UAC helps with privilege control, and EFS is more limited because it encrypts selected files rather than the full device. Microsoft documentation identifies BitLocker as the built-in Windows Pro solution for full-drive encryption and protection against offline data access.

  • A. Correct.

    Correct. BitLocker Drive Encryption is a built-in feature available in Windows Pro editions that provides full-volume encryption. This is the best choice for protecting data on a lost or stolen laptop because it helps prevent unauthorized offline access to the entire drive, including operating system files and user data.

  • B. Incorrect.

    Incorrect. Microsoft Defender Firewall helps control inbound and outbound network traffic, but it does not encrypt data stored on the laptop. It is important for endpoint protection, but it does not address the risk of someone physically obtaining the device and reading the drive.

  • C. Incorrect.

    Incorrect. User Account Control helps limit unauthorized changes by prompting for elevation when administrative actions are attempted. However, UAC does not encrypt stored data and would not protect files if the drive were removed or the system were accessed offline.

  • D. Incorrect.

    Incorrect. Encrypting File System encrypts individual files and folders rather than the entire drive. Although EFS can protect specific data, it is generally not the best answer for lost or stolen portable systems when the goal is broad device-level data protection. BitLocker is the preferred Windows Pro feature for whole-disk protection in this scenario.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam