SY0-701 exam dumps

SY0-701 practice question 87 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 87

Single answerHardware

A security administrator is deploying 50 laptops to employees who frequently travel with sensitive customer data. Management is concerned about someone stealing a laptop and extracting data directly from the drive by removing it and connecting it to another system. The company wants a hardware-based control that protects data at rest with minimal reliance on the operating system. Which of the following is the BEST solution?

  1. A

    Install host-based firewall software on each laptop

  2. B

    Enable full-disk encryption using a Trusted Platform Module (TPM)

  3. C

    Deploy a cable lock for each laptop

  4. D

    Configure UEFI Secure Boot on each device

Show answer and explanation

Correct answer: B

Explanation

The best answer is to enable full-disk encryption with TPM support because the scenario is specifically about protecting sensitive data at rest when a laptop is stolen and the drive may be accessed offline. A TPM is a hardware security component that can securely measure boot integrity and protect cryptographic material used by full-disk encryption solutions. This aligns with common security best practices and enterprise guidance from vendors such as Microsoft for BitLocker deployments and with Trusted Computing Group concepts around hardware-backed key protection. Host-based firewalls and Secure Boot improve endpoint security, but they do not directly address offline data exposure from a removed drive. Cable locks provide physical deterrence but do not provide cryptographic protection for stored data.

  • A. Incorrect.

    This is incorrect. A host-based firewall helps control network traffic to and from the laptop, but it does not protect data stored on the drive if the laptop is stolen and the drive is removed. Someone could still access unencrypted files by mounting the disk on another machine.

  • B. Correct.

    This is correct. Full-disk encryption protects data at rest by encrypting the contents of the drive, and using a TPM provides hardware-backed protection for cryptographic keys. This is the best fit for the scenario because it specifically addresses offline access to a stolen drive while reducing dependence on the operating system alone. In practice, technologies such as BitLocker commonly use a TPM to securely store or protect the keys needed for boot-time integrity and disk decryption.

  • C. Incorrect.

    This is incorrect. A cable lock is a useful physical deterrent in public or office settings, but it does not protect the confidentiality of data if the laptop is stolen anyway or if the drive is removed. It reduces theft risk somewhat, but it does not satisfy the requirement to protect data at rest on the storage device itself.

  • D. Incorrect.

    This is incorrect. UEFI Secure Boot helps ensure that only trusted bootloaders and low-level software are loaded during startup, which is valuable against some boot-level malware. However, it does not encrypt the drive contents and does not prevent an attacker from reading data by removing the disk and connecting it elsewhere.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam