156-536 · Question #42
By default, an FDE Action does what?
The correct answer is C. Encrypts all visible disk volumes. By default, a Full Disk Encryption (FDE) Action in Harmony Endpoint encrypts all visible disk volumes. This ensures that all data stored on the disk is protected through encryption, securing it from unauthorized access even if the device is lost or stolen. The encryption…
Question
By default, an FDE Action does what?
Options
- ARebuilds the hard drive
- BDecrypts all visible disk volumes
- CEncrypts all visible disk volumes
- DRe-defines all visible disk volumes
How the community answered
(39 responses)- A3% (1)
- C95% (37)
- D3% (1)
Explanation
By default, a Full Disk Encryption (FDE) Action in Harmony Endpoint encrypts all visible disk volumes. This ensures that all data stored on the disk is protected through encryption, securing it from unauthorized access even if the device is lost or stolen. The encryption process is applied to all accessible storage volumes on the system.
Topics
Community Discussion
10C is correct, and if you understand what FDE means you should never miss this one again. Full Disk Encryption exists for one purpose, protecting data at rest by encrypting it, so of course the default action of an FDE policy is to encrypt all visible disk volumes. Decrypting would defeat the entire point of deploying the product. Rebuilding or redefining volumes is not even in the same category, those are storage management operations that have nothing to do with encryption policy. Lock this in by tying the answer to the purpose of the tool, not the wording of the option.
The correct answer is C, Encrypts all visible disk volumes. The name itself is your first clue: Full Disk Encryption exists for one default purpose, and that is to encrypt, not to rebuild, redefine, or reverse the process. When an FDE Action is triggered through Check Point Endpoint Security, the agent scans and encrypts every visible disk volume it can reach on the endpoint, which is exactly the behavior the policy engine was designed to enforce by default. Option B is a classic trap because decryption is something FDE can do, but it is not the default action, and the exam loves to test that distinction. Tie this to the Data Protection domain on your blueprint: the default posture is always to protect data at rest by locking it down, not opening it up.
That tracks, and the part worth drilling is that "visible" qualifier, because pre-boot auth volumes and hidden partitions are outside that default sweep, which is exactly where a second question on this topic will try to catch you.
Saw this exact wording show up on my sitting last spring and almost second-guessed myself because "action" sounds too generic, but the default behavior for an FDE Action is C, encrypts all visible disk volumes, which is the whole point of the feature out of the box. Burned that one in by remembering that FDE stands for Full Disk Encryption and the default action has to match the name.
I almost went with B, but FDE literally means Full Disk Encryption, so encrypting is the default action.
FDE means "Full Disk Encryption," so does "Action" here trigger the encryption process by default, or just configure it?
B, because when an FDE Action fires it decrypts the volumes so the system can actually read them.
Good effort, Samuel, but FDE Actions in that context trigger the encryption enforcement policy on the device, not a decryption event, so C is correct because the action initiates or validates that the volume is encrypted per the compliance requirement rather than unlocking it.
Going with B on this one, and here is why the documentation supports it. The FDE Action is triggered after authentication has already occurred, meaning the drive state is encrypted at rest and the action itself performs the decryption to make volumes accessible, which is exactly what the BlackBerry UEM technical reference describes as the default behavior of that action.
Hiroshi, the reference actually supports C here because the FDE Action operates on the activation level, not as a post-authentication decryption trigger, so the behavior you described applies to the lock action, not the FDE Action itself. Re-read section on activation types and you will see the distinction.