Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityEasy
A company is implementing stringent security measures for its remote workforce. They want to ensure that all company-issued laptops, even when used off-network, are protected against unauthorized access to their operating systems and data in case of loss or theft. Which endpoint security best practice directly addresses this concern by making the data unreadable without proper authentication?
- AFull Disk Encryption (FDE)
- BEndpoint Detection and Response (EDR)
- CSecure Boot
- DApplication Whitelisting
Show answer & explanationAnswer & explanation
Correct answer: A. Full Disk Encryption (FDE)
Full Disk Encryption (FDE) encrypts the entire contents of a hard drive, making all data unreadable to anyone without the correct decryption key. This is crucial for protecting data on lost or stolen devices.
Why the other options are wrong
- B. EDR focuses on detecting and responding to threats in real-time, not preventing data access on a physically compromised device.
- C. Secure Boot prevents unauthorized operating systems from loading, but doesn't encrypt data if the OS is not loaded.
- D. Application Whitelisting controls which applications can run, not unauthorized data access on a stolen device.
Full Disk Encryption (FDE)
A security method that encrypts all data on a hard drive, including the operating system, making it unreadable without the correct decryption key.
- Protects data at rest, especially on lost or stolen devices.
- Requires authentication (e.g., password, TPM) to decrypt and access data.
- Common implementations include BitLocker for Windows and FileVault for macOS.
Memory trick: Encrypting your disk is like locking your safe; even if they take the safe, they can't get the valuables.