Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityEasy

A multinational corporation is deploying new laptops to its employees worldwide. Due to the high risk of theft or loss, especially for remote and traveling staff, the company policy dictates that all data on these devices must be rendered unreadable to anyone without proper authorization, even if the device is physically compromised. Which endpoint security technology ensures this data protection requirement?

  1. AFull Disk Encryption (FDE)
  2. BNetwork Access Control (NAC)
  3. CAntivirus/Anti-malware
  4. DEndpoint Detection and Response (EDR)
Show answer & explanation

Correct answer: A. Full Disk Encryption (FDE)

Full Disk Encryption (FDE) encrypts the entire contents of a hard drive, making all data unreadable to anyone without the correct decryption key. This is the primary technology used to protect data at rest on lost or stolen devices, ensuring confidentiality even with physical access.

Why the other options are wrong

  • B. NAC controls network access, not the encryption of data on a device.
  • C. Antivirus/Anti-malware protects against malicious software, not against physical theft and unauthorized data access.
  • D. EDR focuses on detecting and responding to threats, not encrypting data at rest.

Full Disk Encryption (FDE)

A security method that encrypts all data on a hard drive, including the operating system, making it unreadable without the correct decryption key.

  • Protects data at rest, especially on lost or stolen devices.
  • Requires authentication (e.g., password, TPM) to decrypt and access data.
  • Common implementations include BitLocker for Windows and FileVault for macOS.

Memory trick: FDE is like putting all your digital files in a safe that locks the whole hard drive.

More Endpoint Security questions