220-1002 · Question #767
A technician is setting up a laptop for a company. The company is very concerned about data loss after one of a laptops was stolen. Which of the following security best practices should be…
The correct answer is A. Enable full disk encryption. Full disk encryption (FDE), such as BitLocker on Windows, is the best defense against data loss when a laptop is physically stolen. It encrypts the entire drive so that without the correct decryption key or credentials, the data is completely unreadable - even if the drive is…
Question
A technician is setting up a laptop for a company. The company is very concerned about data loss after one of a laptops was stolen. Which of the following security best practices should be implemented to address this concern?
Options
- AEnable full disk encryption.
- BConfigure a failed-attempts lockout.
- CDisable AutoRun.
- DConfigure a BIOS password.
How the community answered
(35 responses)- A86% (30)
- B3% (1)
- C6% (2)
- D6% (2)
Explanation
Full disk encryption (FDE), such as BitLocker on Windows, is the best defense against data loss when a laptop is physically stolen. It encrypts the entire drive so that without the correct decryption key or credentials, the data is completely unreadable - even if the drive is removed and connected to another machine. A failed-attempts lockout (B) and BIOS password (D) only protect against unauthorized login attempts on the running system and can be bypassed by removing the drive. Disabling AutoRun (C) prevents malware from auto-executing from removable media and does not address theft-related data exposure.
Topics
Community Discussion
No community discussion yet for this question.