Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityEasy

A security administrator is configuring a new laptop for a remote employee. The company policy requires that all data on the laptop's hard drive be protected in case the device is lost or stolen. Which endpoint security technology should the administrator implement to meet this requirement?

  1. AFull Disk Encryption (FDE)
  2. BIntrusion Prevention System (IPS)
  3. CHost-based firewall
  4. DAntivirus software
Show answer & explanation

Correct answer: A. Full Disk Encryption (FDE)

Full Disk Encryption (FDE) protects all data stored on the hard drive by encrypting it, rendering the data unreadable to unauthorized individuals if the laptop is lost or stolen.

Why the other options are wrong

  • B. IPS detects and prevents network intrusions, unrelated to data protection on a physically lost device.
  • C. A host-based firewall controls network traffic, not data at rest on a stolen device.
  • D. Antivirus software protects against malware, not against data access on a lost or stolen device.

Full Disk Encryption (FDE)

A security method that encrypts all data on a hard drive, including the operating system, making the data unreadable without the correct decryption key or password.

  • Protects data at rest.
  • Essential for laptops and mobile devices.
  • Prevents unauthorized access if device is lost or stolen.

Memory trick: Encryption locks your data in a digital safe.

More Endpoint Security questions