Workstation Hardening Basics for A+
Short answer
A supportable workstation hardening idea is: reduce the attack surface and protect stored data by (1) using full-disk or file-level encryption for devices that can be lost or stolen; (2) applying firmware passwords to prevent unauthorized boot changes; (3) ensuring default administrative credentials are changed; and (4) disabling AutoRun and services that are not required for the device role. These choices limit both physical and software-based vectors.
Why it appears on the exam
- Given a laptop to be issued to a traveling employee, which combination of settings best reduces data exposure? (Expect answers: enable full-disk encryption, set firmware password, ensure local admin credentials changed.) - Identify which service or feature to disable to prevent automatic malware execution from removable drives (AutoRun). - Recognize a screenshot of firmware settings where a technician must enable a BIOS password and disable external boot.
Key concepts
Concept 1
Required terms
data-at-rest encryption: Encrypting files or entire drives so stored data cannot be read if media are removed or accessed without authorization. BIOS/UEFI password: A password set in firmware to restrict boot configuration changes or prevent unauthorized booting from external media. AutoRun: A Windows feature that automatically executes actions when removable media are inserted; disabling reduces risk of malware autorun.
Example
Enabling BitLocker (Windows) or FileVault (macOS) for data-at-rest encryption on laptops.
Concept 2
How Workstation Hardening Basics works
A supportable workstation hardening idea is: reduce the attack surface and protect stored data by (1) using full-disk or file-level encryption for devices that can be lost or stolen; (2) applying firmware passwords to prevent unauthorized boot changes; (3) ensuring default administrative credentials are changed; and (4) disabling AutoRun and services that are not required for the device role. These choices limit both physical and software-based vectors.
Example
Setting a BIOS/UEFI password to prevent booting from USB without authorization.
Concept 3
Common confusion
Technicians often conflate encryption at transit with encryption at rest; verify the candidate understands device storage encryption is for stolen/lost media. Another confusion is assuming firmware passwords protect OS accounts; they do not replace strong OS account credentials. AutoRun versus AutoPlay terminology can also be mixed up; focus is on preventing automatic execution.
Example
Changing the built-in administrator account name and password on a workstation.
Concept 4
Core 2 (220-1202) question cues
Given a laptop to be issued to a traveling employee, which combination of settings best reduces data exposure? (Expect answers: enable full-disk encryption, set firmware password, ensure local admin credentials changed.); Identify which service or feature to disable to prevent automatic malware execution from removable drives (AutoRun); Recognize a screenshot of firmware settings where a technician must enable a BIOS password and disable external boot.
Example
Disabling AutoRun/AutoPlay so inserting a USB does not auto-execute software.
Sample questions
Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.
Q1.In an A+ question, this detail appears: Enabling BitLocker (Windows) or FileVault (macOS) for data-at-rest encryption on laptops. Which option matches it?
Q2.For this A+ objective, the scenario says: Setting a BIOS/UEFI password to prevent booting from USB without authorization. What is the best match?
Q3.A user reports this support situation: Disabling AutoRun/AutoPlay so inserting a USB does not auto-execute software. Which option should the technician choose?
Practice this lesson in Cultiv8
The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.
Continue in Cultiv8