Which Windows feature provides full-disk encryption by encrypting the entire drive and can require a PIN, password, or startup key before the operating system boots?
BitLocker Drive Encryption is Microsoft's built-in full-disk encryption solution. It encrypts the entire volume and, when configured with a TPM PIN, password, or startup key, blocks access until the correct authentication method is supplied at boot. Encrypting File System (EFS) works only at the file or folder level, System Restore merely rolls system files back to a previous state, and File History is a backup tool; none of these protect the whole drive at startup. [Microsoft Learn - BitLocker overview]
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the role of the TPM in BitLocker?
Open an interactive chat with Bash
How is BitLocker different from Encrypting File System (EFS)?
Open an interactive chat with Bash
What happens if I lose the BitLocker recovery key?