nerdexam
CompTIA

220-1002 · Question #132

A security administrator is developing mobile device hardening standards to protect the confidentiality of data. As part of the baseline the administrator recommends implementing controls to…

The correct answer is D. Full-disk encryption. Full-disk encryption (FDE) protects data confidentiality when a device is physically stolen. If a thief removes the storage or bypasses the OS login, the data is still unreadable without the encryption key. This directly addresses the physical-theft threat model. Two-factor…

Mobile devices

Question

A security administrator is developing mobile device hardening standards to protect the confidentiality of data. As part of the baseline the administrator recommends implementing controls to mitigate risks associated with physical theft. Which of the following would BEST meet the administrator's requirements?

Options

  • ATwo-factor authentication
  • BBIOS passwords
  • CMobile tokenization
  • DFull-disk encryption

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    10% (5)
  • C
    4% (2)
  • D
    83% (40)

Explanation

Full-disk encryption (FDE) protects data confidentiality when a device is physically stolen. If a thief removes the storage or bypasses the OS login, the data is still unreadable without the encryption key. This directly addresses the physical-theft threat model. Two-factor authentication (A) strengthens login security but does not protect data if the storage is accessed offline. BIOS passwords (B) apply to laptops/desktops, not mobile devices, and can often be reset. Mobile tokenization (C) is a payment security technique (replacing card numbers with tokens) and does not protect general device data.

Topics

#full-disk encryption#mobile hardening#data theft#physical security

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice