312-50 exam dumps

312-50 practice question 467 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 467

Single answer▪ Disk Encryption

During an authorized internal security assessment, you are given temporary physical access to a company laptop that uses full-disk encryption with a TPM-only configuration. The employee tells you the laptop was powered off before it was handed over. Your goal is to evaluate whether data at rest is adequately protected if the device is stolen. Which action would provide the strongest evidence that the disk encryption is effectively protecting the data in this scenario?

  1. A

    Boot the laptop from a trusted forensic USB and attempt to mount the internal drive without the recovery key or valid authentication material

  2. B

    Log in with the employee's domain credentials after normal boot and verify that encrypted files can be opened

  3. C

    Run a vulnerability scanner against the laptop's IP address to determine whether the encryption service exposes management ports

  4. D

    Check whether the operating system has a screen lock configured after 5 minutes of inactivity

Show answer and explanation

Correct answer: A

Explanation

The core purpose of full-disk encryption is to protect data at rest, especially in loss or theft scenarios. In a CEH-style assessment, the most relevant test is whether an attacker with physical possession of a powered-off device can bypass the operating system and read the disk offline. Booting from trusted external media and attempting to mount the internal drive is a realistic and defensible validation step. If the data remains inaccessible without the correct recovery key, passphrase, or other valid authentication material, the encryption control is doing its job.

This aligns with common vendor and industry guidance: Microsoft BitLocker documentation emphasizes protection against offline attacks on lost or stolen devices; Apple FileVault documentation similarly describes encryption of the startup disk to prevent unauthorized offline access; and Linux dm-crypt/LUKS is specifically designed to prevent reading block devices without the appropriate key material. In practice, screen locks, user logins, and network scans may support a broader security review, but they do not answer the primary disk-encryption question of whether data remains protected when the machine is powered off.

  • A. Correct.

    Correct. For a powered-off system, full-disk encryption is intended to protect data at rest. A practical way to validate this during an assessment is to boot from trusted external media and attempt offline access to the internal disk. If the drive contents cannot be mounted or read without the proper key material, that is strong evidence the encryption is functioning as intended against theft or loss. This directly tests the security objective of disk encryption rather than general endpoint hardening.

  • B. Incorrect.

    Incorrect. If the system boots normally and you authenticate successfully, the operating system will typically unlock the disk or volumes as part of the trusted boot and user access process. Being able to open files after legitimate authentication does not demonstrate protection against an attacker who steals the laptop while it is powered off. This tests usability, not resistance to offline data access.

  • C. Incorrect.

    Incorrect. Disk encryption products such as BitLocker, FileVault, or LUKS do not rely on exposing a network service on the laptop for the core protection of data at rest. Scanning for open ports may be useful in a broader assessment, but it does not meaningfully validate whether the storage is protected from offline access after theft. This is a common misconception that confuses host/network attack surface with at-rest data protection.

  • D. Incorrect.

    Incorrect. A screen lock helps protect an already-running system from casual local misuse, but it does not validate full-disk encryption on a powered-off device. If a laptop is stolen while shut down, the key security question is whether the drive can be read offline. Screen-lock settings are part of session security, not proof of effective disk encryption.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam