nerdexam
ExamsCAS-001Questions#281
CompTIA

CAS-001 · Question #281

CAS-001 Question #281: Real Exam Question with Answer & Explanation

The correct answer is B: Implement full disk encryption on all storage devices the firm owns.. The key phrase is 'misplaced assets' - lost or stolen physical devices (laptops, USB drives, external drives). Full disk encryption ensures that even if a device is physically lost, the data on it cannot be read without the decryption key. Option B is broader than A because it co

Question

A Chief Information Security Officer (CISO) of a major consulting firm has significantly increased the company's security posture; however, the company is still plagued by data breaches of misplaced assets. These data breaches as a result have led to the compromise of sensitive corporate and client data on at least 25 occasions. Each employee in the company is provided a laptop to perform company business. Which of the following actions can the CISO take to mitigate the breaches?

Options

  • AReload all user laptops with full disk encryption software immediately.
  • BImplement full disk encryption on all storage devices the firm owns.
  • CImplement new continuous monitoring procedures.
  • DImplement an open source system which allows data to be encrypted while processed.

Explanation

The key phrase is 'misplaced assets' - lost or stolen physical devices (laptops, USB drives, external drives). Full disk encryption ensures that even if a device is physically lost, the data on it cannot be read without the decryption key. Option B is broader than A because it covers ALL storage devices the firm owns (not just laptops), including external drives and other portable media. Option A only covers laptops and implies an immediate, rushed rollout. Option C (continuous monitoring) does not protect data on a lost device, and Option D (encryption during processing, similar to homomorphic encryption) does not address data at rest on misplaced hardware.

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice