nerdexam
CompTIA

220-1002 · Question #767

A technician is setting up a laptop for a company. The company is very concerned about data loss after one of a laptops was stolen. Which of the following security best practices should be…

The correct answer is A. Enable full disk encryption. Full disk encryption (FDE), such as BitLocker on Windows, is the best defense against data loss when a laptop is physically stolen. It encrypts the entire drive so that without the correct decryption key or credentials, the data is completely unreadable - even if the drive is…

Hardware

Question

A technician is setting up a laptop for a company. The company is very concerned about data loss after one of a laptops was stolen. Which of the following security best practices should be implemented to address this concern?

Options

  • AEnable full disk encryption.
  • BConfigure a failed-attempts lockout.
  • CDisable AutoRun.
  • DConfigure a BIOS password.

How the community answered

(35 responses)
  • A
    86% (30)
  • B
    3% (1)
  • C
    6% (2)
  • D
    6% (2)

Explanation

Full disk encryption (FDE), such as BitLocker on Windows, is the best defense against data loss when a laptop is physically stolen. It encrypts the entire drive so that without the correct decryption key or credentials, the data is completely unreadable - even if the drive is removed and connected to another machine. A failed-attempts lockout (B) and BIOS password (D) only protect against unauthorized login attempts on the running system and can be bypassed by removing the drive. Disabling AutoRun (C) prevents malware from auto-executing from removable media and does not address theft-related data exposure.

Topics

#full disk encryption#BitLocker#laptop security#data protection

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice