Courseiva
mediumMultiple Select

Encryption Implementation Best Practices

A security policy requires that all data at rest be encrypted. Which TWO of the following are considered best practices for implementing encryption?

Quick Answer

The answer is to use hardware-based encryption if available and to store encryption keys separately from the encrypted data. Hardware-based encryption is considered a best practice because it offloads cryptographic operations to a dedicated processor, reducing exposure to software-based attacks and often providing faster, more secure key management. Separating key storage from the data ensures that even if an attacker gains access to the encrypted files, they cannot decrypt them without the keys, which are stored in a hardened vault or HSM. On the Cisco CyberOps Associate 200-201 exam, this question tests your understanding of defense-in-depth and common implementation pitfalls—a frequent trap is assuming that reusing the same key across systems or relying solely on weak algorithms is acceptable. Remember the mnemonic: "Hardware and separate keys keep the data at ease."

⚠ Common exam trap

200-201 often tests whether candidates confuse 'encryption exists' with 'encryption is done well' — the trap is picking convenience options (single key, weak algorithm) that undermine the security goal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store encryption keys separately from the encrypted data.

Option B is correct because storing encryption keys separately from the encrypted data is a fundamental key-management best practice: it ensures that if the data store is compromised, the attacker does not automatically obtain the keys needed to decrypt it, and it supports separation of duties and use of a dedicated KMS or HSM. Option D is correct because hardware-based encryption (for example, self-encrypting drives, TPMs, or HSMs) offloads cryptographic operations from the CPU, improving performance while providing tamper-resistant key storage and stronger protection of keys at rest. Option A is not a best practice because relying on application-layer encryption alone leaves data unprotected at other layers (disk, database, backup), so defense-in-depth is preferred. Option C is wrong because weak algorithms such as DES or RC4 undermine confidentiality and should never be chosen for performance reasons; strong algorithms like AES-256 are used instead. Option E is wrong because reusing a single key for all data creates a single point of failure and broadens the blast radius of any key compromise; per-data or per-tenant keys with proper rotation are preferred.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement encryption at the application layer only.

    Why it's wrong here

    Application-layer-only encryption leaves data exposed at rest beneath the application, so full-disk or volume encryption is bypassed and the policy is not satisfied. Encrypting within the app is tempting because it protects specific fields and survives storage migration. Best practise is defence in depth: encrypt at both the storage layer and, where warranted, the application layer.

  • ✓

    Store encryption keys separately from the encrypted data.

    Why this is correct

    Separating keys from ciphertext ensures a compromised data store does not expose the keys needed to decrypt it, directly satisfying the policy's data-at-rest protection goal. This is a foundational key-management practise: compromise of one asset must not yield both the locked data and the means to unlock it.

  • ✗

    Use weak encryption algorithms to reduce performance impact.

    Why it's wrong here

    Weak algorithms such as DES or RC4 undermine the policy's confidentiality objective because they are computationally feasible to break, regardless of performance savings. Strong ciphers like AES-256 are the recognised best practise. Reducing CPU overhead is tempting on constrained hardware, but performance tuning is achieved through cipher-mode selection or hardware acceleration, not by weakening the algorithm itself.

  • ✓

    Use hardware-based encryption if available.

    Why this is correct

    Hardware-based encryption offloads cryptographic operations to a dedicated processor, such as a TPM or self-encrypting drive controller, keeping keys outside main memory and reducing CPU overhead. This satisfies the data-at-rest policy while resisting software-based key extraction attacks, making it a recommended best practise where the hardware supports it.

  • ✗

    Use the same key for all data to simplify management.

    Why it's wrong here

    Reusing one key across all data means a single compromise exposes everything and prevents per-dataset rotation, breaching key-management practice. It is tempting because it reduces administrative overhead, and it would be correct only for low-value, non-regulated data where cryptographic isolation is not required.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 200-201

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization's security policy requires that all data at rest on laptops be encrypted. An employee reports that their laptop was stolen. Which control would most likely prevent data exposure?

easy
  • A.Remote wipe
  • B.Biometric authentication
  • ✓ C.Full disk encryption
  • D.Screen lock with password

Why C: Full disk encryption (FDE) is the correct answer because it directly addresses the requirement that data at rest be encrypted. When a laptop is stolen, FDE ensures that the data on the drive is unreadable without the decryption key, which is typically derived from a user password or TPM-stored key. This prevents unauthorized access even if the attacker removes the drive and attempts to read it on another system. The policy explicitly mandates encryption, so FDE is the control that fulfills that requirement.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.