nerdexam
CompTIA

SY0-501 · Question #268

The Chief Executive Officer (CEO) of a major defense contracting company a traveling overseas for a conference. The CEO will be taking a laptop. Which of the following should the security…

The correct answer is B. Full device encryption. When a laptop is lost or stolen, full device encryption ensures that data remains unreadable to unauthorized parties without the encryption key, directly protecting data confidentiality.

Submitted by rachelw· Mar 4, 2026Security architecture

Question

The Chief Executive Officer (CEO) of a major defense contracting company a traveling overseas for a conference. The CEO will be taking a laptop. Which of the following should the security administrator implement to ensure confidentiality of the data if the laptop were to be stolen or lost during the trip?

Options

  • ARemote wipe
  • BFull device encryption
  • CBIOS password
  • DGPS tracking

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    86% (25)
  • C
    7% (2)
  • D
    3% (1)

Why each option

When a laptop is lost or stolen, full device encryption ensures that data remains unreadable to unauthorized parties without the encryption key, directly protecting data confidentiality.

ARemote wipe

Remote wipe requires the device to have network connectivity to receive the wipe command, which cannot be guaranteed if the device is stolen and kept offline, making it an unreliable confidentiality control.

BFull device encryptionCorrect

Full device encryption (such as BitLocker on Windows) encrypts all data on the storage device, rendering it unreadable without the proper decryption key or credentials. Even if the physical drive is removed and placed in another system, the data remains protected. This is the most direct technical control for ensuring data confidentiality in a lost or stolen device scenario.

CBIOS password

A BIOS password prevents unauthorized booting of the device but can be bypassed by physically removing the hard drive and accessing it in another system, so it does not protect the confidentiality of the stored data.

DGPS tracking

GPS tracking helps locate a lost or stolen device but does not prevent an attacker from accessing or reading the data on the device, so it provides no confidentiality protection.

Concept tested: Data confidentiality through full device encryption

Source: https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/bitlocker-overview

Topics

#full disk encryption#data confidentiality#mobile device security#data at rest

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice