CompTIA A+ Core 2 (220-1202)SecurityMedium
A system administrator is configuring security for a new file server that will store highly confidential company documents. The server runs Windows Server 2022. The administrator wants to encrypt the entire system drive, including the operating system, to ensure data confidentiality even if the physical drive is removed from the server. Which Windows feature should be enabled?
- ANTFS Permissions
- BBitLocker
- CWindows Defender
- DEFS (Encrypting File System)
Show answer & explanationAnswer & explanation
Correct answer: B. BitLocker
BitLocker is a full disk encryption feature in Windows that can encrypt entire volumes, including the operating system drive, providing comprehensive data protection against unauthorized access if the drive is stolen.
Why the other options are wrong
- A. NTFS Permissions control access to files and folders but do not encrypt the data at rest on the drive.
- C. Windows Defender is an anti-malware solution, not a disk encryption feature.
- D. EFS encrypts individual files and folders, not the entire drive including the OS.
BitLocker
A full disk encryption feature included with Microsoft Windows that protects data by encrypting entire volumes.
- Encrypts the entire operating system drive and fixed data drives.
- Requires a Trusted Platform Module (TPM) for enhanced security.
- Protects data even if the physical drive is removed and placed in another system.
Memory trick: BitLocker locks the whole disk, EFS locks files.