nerdexam
CompTIA

CAS-003 · Question #155

A company that must comply with regulations is searching for a laptop encryption product to use for its 40,000 end points. The product must meet regulations but also be flexible enough to minimize…

The correct answer is D. A file-based encryption product using profiles to target areas on the file system to encrypt. The question is asking for a solution that will minimize overhead and support in regards to password resets and lockouts. File based encryption products operate under the context of the computer user's user account. This means that the user does not need to remember a separate…

Enterprise Security Architecture

Question

A company that must comply with regulations is searching for a laptop encryption product to use for its 40,000 end points. The product must meet regulations but also be flexible enough to minimize overhead and support in regards to password resets and lockouts. Which of the following implementations would BEST meet the needs?

Options

  • AA partition-based software encryption product with a low-level boot protection and authentication
  • BA container-based encryption product that allows the end users to select which files to encrypt
  • CA full-disk hardware-based encryption product with a low-level boot protection and authentication
  • DA file-based encryption product using profiles to target areas on the file system to encrypt

How the community answered

(68 responses)
  • A
    12% (8)
  • B
    3% (2)
  • C
    7% (5)
  • D
    78% (53)

Explanation

The question is asking for a solution that will minimize overhead and support in regards to password resets and lockouts. File based encryption products operate under the context of the computer user's user account. This means that the user does not need to remember a separate password for the encryption software. If the user forgets his user account password or is locked out due to failed login attempts, the support department can reset his password from a central database of user accounts (such as Active Directory) without the need to visit the user's computer. Profiles can be used to determine areas on the file system to encrypt such as Document folders.

Topics

#full disk encryption#endpoint security#key management#compliance

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice