Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsHard
A financial institution is developing a new mobile banking application. The security team insists that all sensitive data stored on the mobile device must be protected even if the device is lost or stolen. Which endpoint security concept is critical to implement for this requirement?
- ANetwork Access Control (NAC)
- BFull Disk Encryption (FDE)
- CEndpoint Detection and Response (EDR)
- DApplication Whitelisting
Show answer & explanationAnswer & explanation
Correct answer: B. Full Disk Encryption (FDE)
Full Disk Encryption (FDE) protects all data on a device at rest by encrypting the entire storage volume. If the device is lost or stolen, the data remains unreadable without the correct decryption key, directly addressing the requirement to protect sensitive data on a lost or stolen device.
Why the other options are wrong
- A. NAC controls which devices can access the network, not how data is protected on the device itself.
- C. EDR monitors for and responds to threats on endpoints in real-time, but doesn't primarily protect data on a lost/stolen device.
- D. Application Whitelisting restricts which applications can run, but doesn't protect data at rest if the device is compromised.
Full Disk Encryption (FDE)
A security feature that encrypts all data on a hard drive or storage device, protecting it from unauthorized access if the device is lost, stolen, or accessed by an unauthorized party.
- Encrypts the entire storage volume, including operating system and user data.
- Data is unreadable without the correct decryption key or password.
- Protects 'data at rest'.
- Commonly implemented on laptops, desktops, and mobile devices.
Memory trick: Endpoint security guards the device itself, like FDE locking all its data.