A bank insists all of its vendors must prevent data loss on stolen laptops. Which of the following strategies is the bank requiring?
Choose an answer
Tap an option to check your answer.
Correct answer: Encryption at rest.
Why this is the answer
Encryption at rest is the correct strategy because it protects data stored on a device, such as a laptop's hard drive, by rendering it unreadable without the correct decryption key. If a laptop is stolen, the encrypted data remains secure and inaccessible to unauthorized individuals, thus preventing data loss in the context of confidentiality. Masking replaces sensitive data with non-sensitive equivalents, which is useful for testing environments but doesn't protect the original data on a stolen device. Data classification categorizes data based on its sensitivity, which is a prerequisite for applying security controls but not a control itself. Permission restrictions control who can access data, but they become irrelevant if the device itself is compromised and removed from the controlled environment.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed