CompTIA A+ Core 2 (220-1202)SecurityHard
A system administrator is configuring security for a new file server. They want to ensure that files stored on the server are protected at rest and that the entire volume is encrypted, even if the physical drive is removed from the server. Which Windows feature should the administrator implement to meet this requirement?
- AWindows Defender
- BBitLocker
- CNTFS Permissions
- DEncrypting File System (EFS)
Show answer & explanationAnswer & explanation
Correct answer: B. BitLocker
BitLocker is Windows' full-disk encryption feature that encrypts an entire volume, protecting all data at rest. If the drive is removed from the server and placed into another system, the data remains encrypted and inaccessible without the correct decryption key, fulfilling the requirement for protection even if the physical drive is removed.
Why the other options are wrong
- A. Windows Defender provides anti-malware protection, not full-disk encryption.
- C. NTFS permissions control access to files and folders while the system is running, but do not encrypt data if the drive is accessed externally.
- D. EFS encrypts individual files and folders, not entire volumes.
BitLocker
A full-disk encryption feature included with Microsoft Windows that encrypts entire volumes to protect data at rest.
- Encrypts operating system drives, fixed data drives, and removable data drives.
- Can integrate with a Trusted Platform Module (TPM) for enhanced security.
- Protects data even if the physical drive is stolen or removed from the system.
Memory trick: Encrypt your data with BitLocker for full drive protection.