Objective 2.1

220-1202

Summarize various security measures and their purposes.

Objective 2.1 sits in Security, which carries 28% of the A+ Core 2 exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

2-1Security

Which BitLocker startup authentication option is discouraged and disabled by default because there is no lockout logic to stop repeated guessing attempts?

PIN entered at the BitLocker preboot screenA PIN is used alongside a TPM check and is not the option described as brute-force vulnerable and disabled by default.
Password entered at the BitLocker preboot screenCorrect · your answerCorrect: this option lacks lockout protection and is disabled by default.
Startup key stored on a removable USB driveA startup key is a physical file on removable media, not the password-lockout weakness described here.
TPM-based hardware integrity check at startupA TPM check verifies device integrity and is unrelated to the password lockout limitation described.

Correct.

Checked against learn.microsoft.com, July 2026

Concept

BitLocker offers several startup authentication options on devices without a TPM, and each carries different security tradeoffs.

Why B

The password option is not secure because it has no lockout logic against brute force attempts, so it is discouraged and disabled by default.

Source

Use a password. This option isn't secure since it's subject to brute force attacks as there isn't a password lockout logic. As such, the password option is discouraged and disabled by default.

Microsoft Learn: BitLocker, checked July 2026
#bitlocker#encryption#authentication#security

Now you: objective 2.1 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 2

2-1Security

A technician configures a laptop so that, in addition to a successful TPM check, the user must also enter a PIN before Windows will continue booting. Which security concept does this setup provide?

Sample question 2 of 2

2-1Security

A manager asks a technician to put a new marketing hire into the Domain Admins group so that later requests will be quicker to fulfil. The hire's job needs only the shared marketing folder. Which security principle should guide the rights the technician assigns?

Full A+ Core 2 question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security