CAS-002 · Question #825
A company that must comply with regulations is searching for a laptop encryption product to use for its 40,000 end points. The product must meet regulations but also be flexible enough to minimize…
The correct answer is D. A file-based encryption product using profiles to target areas on the file system to encrypt. File-based encryption using profiles meets regulatory requirements while integrating with existing enterprise identity systems, minimizing password reset and lockout support overhead at scale.
Question
A company that must comply with regulations is searching for a laptop encryption product to use for its 40,000 end points. The product must meet regulations but also be flexible enough to minimize overhead and support in regards to password resets and lockouts. Which of the following implementations would BEST meet the needs?
Options
- AA partition-based software encryption product with a low-level boot protection and authentication
- BA container-based encryption product that allows the end users to select which files to encrypt
- CA full-disk hardware-based encryption product with a low-level boot protection and authentication
- DA file-based encryption product using profiles to target areas on the file system to encrypt
How the community answered
(26 responses)- A12% (3)
- B4% (1)
- C15% (4)
- D69% (18)
Why each option
File-based encryption using profiles meets regulatory requirements while integrating with existing enterprise identity systems, minimizing password reset and lockout support overhead at scale.
Partition-based encryption with low-level boot protection introduces a separate pre-boot authentication layer, which creates additional password reset and lockout scenarios not handled by standard enterprise identity management.
A container-based product that lets end users select which files to encrypt is inconsistent and unreliable for regulatory compliance, as users may omit required data.
Full-disk hardware-based encryption with pre-boot authentication requires out-of-band recovery processes for locked-out users and is more operationally complex to manage at large scale.
A file-based encryption product with policy profiles can target regulated data locations and leverage existing Active Directory or SSO credentials, so password resets follow standard enterprise helpdesk processes rather than requiring specialized recovery procedures. At 40,000 endpoints, this dramatically reduces support overhead compared to solutions that require separate pre-boot authentication credentials. Targeted profiles also provide flexibility to adjust encryption scope as regulatory requirements evolve without requiring full disk re-encryption.
Concept tested: File-based encryption with profiles for enterprise compliance
Source: https://csrc.nist.gov/publications/detail/sp/800-111/final
Topics
Community Discussion
No community discussion yet for this question.