220-1102 Question 684
Single answerRisk analysisA small medical office is replacing several older laptops used for patient scheduling and billing. During planning, a technician learns that the laptops store spreadsheets containing patient names, appointment details, and insurance account numbers. The office manager says the systems are rarely taken off-site, so encryption can be skipped to save time. Which action best reflects proper risk analysis for this situation?
- A
Recommend full-disk encryption because the potential impact of exposing sensitive patient and financial data is high, even if the likelihood of theft is considered moderate or low
- B
Skip encryption because laptops that remain in the office do not present a meaningful confidentiality risk
- C
Focus only on installing antivirus because malware is a more common threat than device loss or unauthorized physical access
- D
Wait until a laptop is actually lost before proposing additional safeguards so the office can avoid unnecessary costs
Show answer and explanation
Correct answer: A
Explanation
The best answer is to recommend full-disk encryption based on the risk presented by sensitive data stored on portable devices. In A+ Core 2, risk analysis focuses on assessing the likelihood of a threat and the business impact if it occurs. A laptop that contains patient and financial data can create a serious confidentiality incident even if it is not frequently removed from the office. Best practices from major security frameworks, such as NIST guidance on protecting data confidentiality and minimizing risk through appropriate safeguards, support using encryption on endpoints that store sensitive information. The key exam objective is recognizing that risk is not judged by likelihood alone; high-impact data exposure often justifies stronger preventive controls.
- A. Correct.
Correct. Risk analysis considers both likelihood and impact. Even if these laptops are usually kept on-site, portable devices still face risks such as theft, improper disposal, unauthorized access, or accidental loss. Because the data includes patient and billing information, the impact of disclosure is significant. A practical recommendation is to reduce risk with full-disk encryption, which is a standard safeguard for sensitive data on mobile endpoints.
- B. Incorrect.
Incorrect. This choice underestimates the risk by focusing only on one factor: where the laptops are usually located. Confidentiality risk still exists inside an office due to theft, insider misuse, break-ins, or equipment leaving the building for repair or replacement. Risk analysis does not dismiss a control simply because the likelihood seems lower.
- C. Incorrect.
Incorrect. Antivirus is important, but this answer reflects a common mistake: treating the most familiar threat as the only threat. Proper risk analysis evaluates multiple threat types, including physical loss, unauthorized access, and data exposure. Antivirus does not protect data at rest if a laptop is stolen or accessed offline.
- D. Incorrect.
Incorrect. This is a reactive approach rather than a risk-based one. Risk analysis is used to identify and mitigate issues before an incident occurs. Waiting for an actual loss event is poor security practice, especially when the systems store regulated or sensitive information.