SY0-701 exam dumps

SY0-701 practice question 136 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 136

Single answerEncryption

A company is deploying full-disk encryption on employee laptops that store sensitive customer data. During testing, the security team discovers that several users can still remove the laptop drive, connect it to another system, and read some files because the encryption key is being released automatically at boot with no hardware-based integrity check. The company wants to reduce the risk of offline attacks while keeping the startup process practical for users. Which solution BEST addresses this requirement?

  1. A

    Implement BitLocker or a similar full-disk encryption solution with TPM-backed key storage and require a pre-boot PIN

  2. B

    Replace full-disk encryption with NTFS file permissions so only authorized users can access the files after logon

  3. C

    Use hashing on the drive contents so altered files cannot be read when the drive is moved to another system

  4. D

    Store the disk encryption recovery key in a plaintext file on the laptop so users can recover access if the TPM fails

Show answer and explanation

Correct answer: A

Explanation

The best answer is to use full-disk encryption with TPM-backed key protection and a pre-boot PIN. In laptop theft scenarios, the primary concern is offline access to stored data. Full-disk encryption protects confidentiality, and a TPM helps ensure the encryption key is released only when the system boots in an expected state. Requiring a pre-boot PIN strengthens protection against attackers who have physical possession of the device. This approach aligns with widely accepted best practices from platform vendors and security guidance, including Microsoft BitLocker deployment recommendations and NIST guidance on protecting data at rest. File permissions do not protect data once the drive is removed from the original OS context, hashing does not provide confidentiality, and storing recovery keys insecurely on the endpoint defeats the purpose of encryption.

  • A. Correct.

    Correct. Using full-disk encryption with a Trusted Platform Module (TPM) helps bind key release to the device's measured boot state, reducing the chance that an attacker can simply remove the drive and access data elsewhere. Adding a pre-boot PIN provides an additional authentication factor beyond the device itself, which significantly improves resistance to offline theft scenarios while remaining practical for users.

  • B. Incorrect.

    Incorrect. NTFS permissions are an access control mechanism enforced by the operating system after boot, not an encryption control. If an attacker removes the drive and mounts it elsewhere, file permissions alone do not protect the underlying data in the same way full-disk encryption does.

  • C. Incorrect.

    Incorrect. Hashing provides integrity checking, not confidentiality. A hash does not prevent someone from reading data if they can access the drive. This option reflects a common misconception that hashing can substitute for encryption.

  • D. Incorrect.

    Incorrect. Recovery keys should be protected and stored securely, such as in an enterprise key escrow solution or directory service, not in plaintext on the same laptop. Keeping the recovery key on the device undermines the protection provided by disk encryption because an attacker who steals the laptop may obtain both the encrypted data and the key.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam