I think that the best should mean something like FileVault on Mac OS X, because the system disk is well encrypted and you don't need to enter the key password when you boot the system.
O BitLocker é o equivalente do Windows do FileVault.
I also read some info about VeraCrypt (https://www.veracrypt.fr/en/Downloads.html), and it works the same way (you will need an external USB drive).
O VeraCrypt suporta o FDE do disco do sistema, em outras palavras, você pode criptografar o disco em que o Windows está instalado.
Isn't really any other way to encrypt the system drive without having the TPM module or an external USB drive mounted on the device?
I searched some info about BitLocker on Windows, with and without the TPM module (https://www.howtogeek.com/howto/6229/how-to-use-bitlocker-on-drives-without-tpm/), but if you don't have the TPM module you will need and external USB drive to save the key on.
O backup de sua chave de recuperação é uma etapa opcional, o BitLocker, pode ser usado em um sistema sem um TPM. Então, infelizmente, parece que você eliminou os dois únicos métodos, para realizar a Criptografia de Disco Completo com o Windows (BitLocker e VeraCrypt / TrueCrypt).