CompTIA Tech+ (FC0-U71)SecurityMedium

A company policy dictates that all sensitive data stored on laptops must be encrypted. A technician is configuring a new laptop for an executive and needs to ensure that the entire hard drive is encrypted, including the operating system files, so that if the laptop is lost or stolen, the data remains unreadable. Which type of encryption should the technician implement?

  1. AFull disk encryption (FDE)
  2. BApplication-level encryption
  3. CFolder-level encryption
  4. DFile-level encryption
Show answer & explanation

Correct answer: A. Full disk encryption (FDE)

Full disk encryption (FDE) encrypts every sector of a disk, ensuring that all data, including the operating system, user files, and temporary files, is protected. This is crucial for protecting data if a device is lost or stolen.

Why the other options are wrong

  • B. Application-level encryption encrypts data generated or used by a specific application, not the entire disk.
  • C. Folder-level encryption encrypts all files within a specific folder, but not the entire drive.
  • D. File-level encryption encrypts individual files, leaving other parts of the disk unencrypted.

Full Disk Encryption (FDE)

A security method that encrypts all data on a hard drive, including the operating system, preventing unauthorized access if the device is lost or stolen.

  • Encrypts every sector of the disk.
  • Protects data at rest.
  • Requires a password or key at boot-up.

Memory trick: From Full Disk to File, each level protects less.

More Security questions