220-1102 · Question #349
A user's corporate laptop with proprietary work information was stolen from a coffee shop. The user logged in to the laptop with a simple password, and no other security mechanisms were in place…
The correct answer is B. Full disk encryption. Full disk encryption is the most effective control to prevent recovery of data from a stolen laptop when other security mechanisms like strong passwords or multi-factor authentication are not present.
Question
A user's corporate laptop with proprietary work information was stolen from a coffee shop. The user logged in to the laptop with a simple password, and no other security mechanisms were in place. Which of the following would MOST likely prevent the stored data from being recovered?
Options
- ABiometrics
- BFull disk encryption
- CEnforced strong system password
- DTwo-factor authentication
How the community answered
(21 responses)- A5% (1)
- B76% (16)
- C14% (3)
- D5% (1)
Why each option
Full disk encryption is the most effective control to prevent recovery of data from a stolen laptop when other security mechanisms like strong passwords or multi-factor authentication are not present.
Biometrics authenticate the user to the system but do not protect data on the disk if the disk is removed and accessed directly.
Full disk encryption (FDE) encrypts all data on the hard drive, making it unreadable without the correct decryption key, thereby protecting data even if the attacker bypasses login credentials or removes the drive.
An enforced strong system password protects access to the operating system but would not prevent an attacker from removing the hard drive and accessing the data directly from another system.
Two-factor authentication adds an extra layer of security to the login process but does not protect data if the physical storage device is removed and accessed independently.
Concept tested: Data at rest protection
Source: https://learn.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-overview
Topics
Community Discussion
No community discussion yet for this question.