A+ Lesson

Workstation Hardening Basics for A+

Last updated: 6/10/2026

Short answer

A supportable workstation hardening idea is: reduce the attack surface and protect stored data by (1) using full-disk or file-level encryption for devices that can be lost or stolen; (2) applying firmware passwords to prevent unauthorized boot changes; (3) ensuring default administrative credentials are changed; and (4) disabling AutoRun and services that are not required for the device role. These choices limit both physical and software-based vectors.

Why it appears on the exam

- Given a laptop to be issued to a traveling employee, which combination of settings best reduces data exposure? (Expect answers: enable full-disk encryption, set firmware password, ensure local admin credentials changed.) - Identify which service or feature to disable to prevent automatic malware execution from removable drives (AutoRun). - Recognize a screenshot of firmware settings where a technician must enable a BIOS password and disable external boot.

Key concepts

Concept 1

Required terms

data-at-rest encryption: Encrypting files or entire drives so stored data cannot be read if media are removed or accessed without authorization. BIOS/UEFI password: A password set in firmware to restrict boot configuration changes or prevent unauthorized booting from external media. AutoRun: A Windows feature that automatically executes actions when removable media are inserted; disabling reduces risk of malware autorun.

Example

Enabling BitLocker (Windows) or FileVault (macOS) for data-at-rest encryption on laptops.

Concept 2

How Workstation Hardening Basics works

A supportable workstation hardening idea is: reduce the attack surface and protect stored data by (1) using full-disk or file-level encryption for devices that can be lost or stolen; (2) applying firmware passwords to prevent unauthorized boot changes; (3) ensuring default administrative credentials are changed; and (4) disabling AutoRun and services that are not required for the device role. These choices limit both physical and software-based vectors.

Example

Setting a BIOS/UEFI password to prevent booting from USB without authorization.

Concept 3

Common confusion

Technicians often conflate encryption at transit with encryption at rest; verify the candidate understands device storage encryption is for stolen/lost media. Another confusion is assuming firmware passwords protect OS accounts; they do not replace strong OS account credentials. AutoRun versus AutoPlay terminology can also be mixed up; focus is on preventing automatic execution.

Example

Changing the built-in administrator account name and password on a workstation.

Concept 4

Core 2 (220-1202) question cues

Given a laptop to be issued to a traveling employee, which combination of settings best reduces data exposure? (Expect answers: enable full-disk encryption, set firmware password, ensure local admin credentials changed.); Identify which service or feature to disable to prevent automatic malware execution from removable drives (AutoRun); Recognize a screenshot of firmware settings where a technician must enable a BIOS password and disable external boot.

Example

Disabling AutoRun/AutoPlay so inserting a USB does not auto-execute software.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.In an A+ question, this detail appears: Enabling BitLocker (Windows) or FileVault (macOS) for data-at-rest encryption on laptops. Which option matches it?

Q2.For this A+ objective, the scenario says: Setting a BIOS/UEFI password to prevent booting from USB without authorization. What is the best match?

Q3.A user reports this support situation: Disabling AutoRun/AutoPlay so inserting a USB does not auto-execute software. Which option should the technician choose?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8