easyMultiple Choice
200-201 Practice Question: An organization's security policy requires that…
An organization's security policy requires that all data at rest on laptops be encrypted. An employee reports that their laptop was stolen. Which control would most likely prevent data exposure?
⚠ Common exam trap
It's easy for candidates to confuse access controls (biometrics, screen lock) with encryption controls; candidates might think that a screen lock prevents data exposure, but it only protects the running system, not the data at rest.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Full disk encryption
Full disk encryption (FDE) is the correct answer because it directly addresses the requirement that data at rest be encrypted. When a laptop is stolen, FDE ensures that the data on the drive is unreadable without the decryption key, which is typically derived from a user password or TPM-stored key. This prevents unauthorized access even if the attacker removes the drive and attempts to read it on another system. The policy explicitly mandates encryption, so FDE is the control that fulfills that requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remote wipe
Why it's wrong here
Remote wipe requires the laptop to reconnect to a network and receive the command; offline data stays readable until then. Remote wipe suits lost devices still online, whereas full-disk encryption renders the data unreadable immediately upon theft.
- ✗
Biometric authentication
Why it's wrong here
Biometric authentication gates login, but the disk remains unencrypted, so an attacker can read it via another machine or by removing the drive. Biometrics suit controlling access to a running session, not protecting data at rest on stolen hardware.
- ✓
Full disk encryption
Why this is correct
Full disk encryption renders the laptop's stored data unreadable without the decryption key, so a thief cannot extract files from the stolen drive. It satisfies the data-at-rest encryption requirement directly, unlike access controls or network-based protections that the attacker bypasses by possessing the device.
- ✗
Screen lock with password
Why it's wrong here
A screen lock only gates interactive access after boot; an attacker can remove the drive and read it directly, bypassing the lock entirely. Screen locks suit preventing casual physical access to a running session, not protecting data at rest on a stolen device.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.