nerdexam
CompTIA

220-1101 · Question #106

The IT department at an insurance brokerage needs to acquire laptops that have built-in fingerprint readers in order to create a more secure environment. Which of the following would be the MOST secur

The correct answer is B. Restrict device access to only the user to whom the laptop is assigned.. The purpose of a fingerprint reader is biometric authentication - verifying that the person accessing the device is the authorized user. The most secure implementation is to enroll only the assigned user's fingerprint on each laptop, so that only that individual can unlock the de

Hardware

Question

The IT department at an insurance brokerage needs to acquire laptops that have built-in fingerprint readers in order to create a more secure environment. Which of the following would be the MOST secure way to implement the fingerprint readers?

Options

  • AGrant all registered employees access to each machine.
  • BRestrict device access to only the user to whom the laptop is assigned.
  • CLimit device access to departments and guest users.
  • DGive each team member a USB drive that bypasses the reader to allow guest users to log in.

How the community answered

(54 responses)
  • A
    4% (2)
  • B
    81% (44)
  • C
    6% (3)
  • D
    9% (5)

Explanation

The purpose of a fingerprint reader is biometric authentication - verifying that the person accessing the device is the authorized user. The most secure implementation is to enroll only the assigned user's fingerprint on each laptop, so that only that individual can unlock the device. This enforces strict one-to-one access control. Granting all employees access to each machine (A) completely defeats the security purpose of biometrics. Limiting access to departments and guests (C) still grants access to multiple unintended individuals. Providing a USB bypass for guests (D) creates a deliberate security hole that undermines the entire biometric access control system.

Topics

#Biometric security#Access control#Laptop security#Authentication

Community Discussion

No community discussion yet for this question.

Full 220-1101 Practice