Courseiva
easyMultiple Choice

200-201 Practice Question: An organization's security policy requires that…

An organization's security policy requires that all data at rest on laptops be encrypted. An employee reports that their laptop was stolen. Which control would most likely prevent data exposure?

⚠ Common exam trap

It's easy for candidates to confuse access controls (biometrics, screen lock) with encryption controls; candidates might think that a screen lock prevents data exposure, but it only protects the running system, not the data at rest.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Full disk encryption

Full disk encryption (FDE) is the correct answer because it directly addresses the requirement that data at rest be encrypted. When a laptop is stolen, FDE ensures that the data on the drive is unreadable without the decryption key, which is typically derived from a user password or TPM-stored key. This prevents unauthorized access even if the attacker removes the drive and attempts to read it on another system. The policy explicitly mandates encryption, so FDE is the control that fulfills that requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remote wipe

    Why it's wrong here

    Remote wipe requires the laptop to reconnect to a network and receive the command; offline data stays readable until then. Remote wipe suits lost devices still online, whereas full-disk encryption renders the data unreadable immediately upon theft.

  • ✗

    Biometric authentication

    Why it's wrong here

    Biometric authentication gates login, but the disk remains unencrypted, so an attacker can read it via another machine or by removing the drive. Biometrics suit controlling access to a running session, not protecting data at rest on stolen hardware.

  • ✓

    Full disk encryption

    Why this is correct

    Full disk encryption renders the laptop's stored data unreadable without the decryption key, so a thief cannot extract files from the stolen drive. It satisfies the data-at-rest encryption requirement directly, unlike access controls or network-based protections that the attacker bypasses by possessing the device.

  • ✗

    Screen lock with password

    Why it's wrong here

    A screen lock only gates interactive access after boot; an attacker can remove the drive and read it directly, bypassing the lock entirely. Screen locks suit preventing casual physical access to a running session, not protecting data at rest on a stolen device.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.