A company's IT policy requires the protection of sensitive data on employee laptops, especially those taken off premises. Recently, data theft on these devices has become a concern. Which of the following security measures should the company implement to safeguard the laptops?
Full disk encryption is the most effective security measure for safeguarding sensitive data on employee laptops.
Full disk encryption ensures that all data stored on a laptop's hard drive is encrypted, making it inaccessible without the proper credentials. This is especially crucial for laptops that are taken off premises, as they are more vulnerable to theft or unauthorized access.
This choice is the best option because it protects all data on the device by encrypting the entire disk. If a laptop is lost or stolen, the data remains secure as it cannot be accessed without the correct decryption key or password, safeguarding sensitive information effectively.
While intrusion detection software is useful for monitoring and identifying unauthorized access attempts, it does not directly protect data stored on the laptop itself. If a device is stolen, this software will not prevent data breaches, as it focuses on network threats rather than securing data at rest.
Biometric authentication enhances security by verifying the identity of the user, but it only controls access to the device. If a laptop is stolen while powered on or if the data is not encrypted, the thief could still access sensitive information, making this measure insufficient on its own.
VPN access provides a secure connection to the internet, protecting data in transit. However, it does not encrypt or secure data stored on the laptop itself. If a device is compromised or stolen, any unprotected data on the hard drive remains vulnerable.
To safeguard sensitive data on employee laptops, especially those taken off premises, full disk encryption emerges as the most effective measure. By encrypting all information stored on the device, it ensures that even if a laptop is stolen, the data remains secure and inaccessible. Other measures, while valuable for different aspects of security, do not directly protect data at rest and therefore cannot substitute for the comprehensive protection that full disk encryption offers.
Related Questions
View allA technician replaced a failed PSU on a high-end workstation PC. Now,...
A client provides a large spreadsheet to a business analyst for review...
Which of the following connection types has the highest average signal...
An online retailer wants to save money and is considering migrating to...
Company employees do not have assigned workspaces and regularly work a...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus 501 Practice Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations