312-50 exam dumps

312-50 practice question 465 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 465

Single answer▪ Disk Encryption

During an authorized security assessment, a consultant is given temporary physical access to a company-issued Windows 11 laptop that is reported missing and later recovered. The drive uses BitLocker full-disk encryption with TPM-only protection enabled, and the laptop is currently powered off. The client wants to know whether a thief who stole only the powered-off device would likely be able to read files by simply removing the SSD and connecting it to another system. Which assessment conclusion is MOST accurate?

  1. A

    The data would likely remain protected because BitLocker encrypts the volume, and removing the SSD from a powered-off system does not provide transparent access to the files.

  2. B

    The data would be readable because TPM-only protection stores the BitLocker key on the motherboard, so moving the SSD bypasses encryption checks.

  3. C

    The data would be readable if the attacker uses NTFS forensic tools, because file system parsing defeats BitLocker once the drive is mounted externally.

  4. D

    The data would be readable because full-disk encryption only protects the operating system files, not user documents stored in the same volume.

Show answer and explanation

Correct answer: A

Explanation

The most accurate conclusion is that BitLocker protects data at rest against offline theft scenarios such as drive removal from a powered-off device. In a CEH context, this is an important defensive control to recognize during post-exploitation, physical security, and data protection assessments. TPM-only mode is weaker than using TPM with a PIN against certain pre-boot attack scenarios, but it still does not allow a stolen, powered-off SSD to be read merely by attaching it to another computer. Microsoft BitLocker documentation and common enterprise hardening guidance consistently describe BitLocker as protection against offline attacks, including attempts to access data by booting another OS or moving the disk to another machine. However, assessors should also understand the limits: if the device is already powered on, unlocked, or keys are otherwise obtained from memory, recovery material, or poor key management practices, the risk changes significantly.

  • A. Correct.

    Correct. BitLocker full-volume encryption is specifically designed to protect data at rest. When a Windows system is powered off, the encrypted volume cannot be read just by removing the SSD and attaching it to another machine. TPM-only mode helps automatically unlock the drive during normal boot on the original platform, but it does not mean the raw disk contents become readable elsewhere. Without the appropriate decryption material, the external system will see encrypted data rather than usable files.

  • B. Incorrect.

    Incorrect. This reflects a common misunderstanding of TPM-based protection. The TPM helps protect key material and validates platform conditions during boot, but it does not make the drive readable when moved to another system. In fact, removing the SSD from the original device generally prevents transparent unlock because the expected TPM and boot measurements are no longer present.

  • C. Incorrect.

    Incorrect. NTFS forensic or file system analysis tools can parse metadata only after the underlying data is accessible. BitLocker encryption occurs below the file system layer for the protected volume, so an examiner cannot simply bypass encryption by using NTFS tools on an externally attached encrypted disk. The misconception here is confusing file system analysis with cryptographic access.

  • D. Incorrect.

    Incorrect. Full-disk or full-volume encryption such as BitLocker protects the contents of the encrypted volume, including operating system files and user data stored on that volume. It is not limited to OS files. Someone might choose this option if they confuse disk encryption with selective file encryption technologies such as EFS.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam