CompTIA Tech+ (FC0-U71)Applications and SoftwareMedium
A technician is setting up a new Windows 10 workstation for a user who frequently travels and handles sensitive client data. To protect the data in case the laptop is lost or stolen, the technician needs to ensure that the entire hard drive is encrypted without requiring manual user intervention at every boot, while still offering robust security. Which Windows feature should be enabled and configured?
- ABitLocker
- BSystem Restore
- CWindows Defender Firewall
- DUser Account Control (UAC)
Show answer & explanationAnswer & explanation
Correct answer: A. BitLocker
BitLocker is a full-disk encryption feature in Windows that encrypts the entire drive, protecting data even if the device is stolen. It can be configured to integrate with a Trusted Platform Module (TPM) for seamless, automatic decryption at boot, meeting the 'without requiring manual user intervention' requirement.
Why the other options are wrong
- B. System Restore rolls back system files to a previous state and does not encrypt data.
- C. Windows Defender Firewall controls network access and does not encrypt the hard drive.
- D. User Account Control (UAC) manages application permissions and privilege elevation, not disk encryption.
BitLocker
A full-disk encryption feature in Microsoft Windows that protects data by encrypting entire volumes.
- Encrypts entire hard drives.
- Integrates with Trusted Platform Module (TPM) for hardware-based security.
- Protects data at rest and during boot-up.
Memory trick: BitLocker locks the whole disk, TPM helps turn the key.