CompTIA Server+ (SK0-005)Security and Disaster RecoveryEasy

A server administrator is implementing a data security policy that requires all data at rest on server hard drives to be encrypted. The solution must provide encryption for the entire disk, including the operating system, and allow for secure boot. Which technology would be most appropriate for this requirement?

  1. AFile-level encryption
  2. BNetwork share encryption
  3. CDatabase encryption
  4. DFull Disk Encryption (FDE)
Show answer & explanation

Correct answer: D. Full Disk Encryption (FDE)

Full Disk Encryption (FDE) encrypts all data on a disk, including the operating system, boot sectors, and user data. This ensures that if the physical drive is removed, its contents remain unreadable without the correct decryption key, fulfilling the requirement for 'all data at rest on server hard drives' and 'entire disk, including the operating system'.

Why the other options are wrong

  • A. File-level encryption encrypts individual files or directories, leaving the OS and other parts of the disk unencrypted.
  • B. Network share encryption protects data transmitted or stored on a network share, not the local server's hard drives.
  • C. Database encryption protects data within a database, but not the entire server disk.

Full Disk Encryption (FDE)

A method of encrypting all data on a disk drive, ensuring that all information, including the operating system, is protected.

  • Protects data at rest from unauthorized access if the drive is stolen.
  • Requires a pre-boot authentication factor (e.g., password, TPM).
  • Examples include BitLocker (Windows) or LUKS (Linux).

Memory trick: Encryption Levels: From a single file to the 'Full Disk'!

More Security and Disaster Recovery questions