Courseiva
Security →hardMultiple Choice

FC0-U71 Security Practice Question

A security administrator wants to protect data at rest on a laptop that may be lost or stolen. Which of the following is the BEST solution?

⚠ Common exam trap

FC0-U71 often tests the distinction between data-at-rest and data-in-transit controls — candidates pick VPN or firewall when the scenario is specifically about a lost/stolen device.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable full disk encryption

Full disk encryption (FDE) protects data at rest by encrypting the entire volume, so if the laptop is lost or stolen the data is unreadable without the decryption key. This directly addresses the threat of physical device compromise, which is the scenario described.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a VPN when connecting to the internet

    Why it's wrong here

    A VPN encrypts data in transit, leaving the laptop's stored files readable once the disk is removed or the device booted. It tempts because VPNs are the standard answer for protecting data on untrusted networks, which is the correct choice when the risk is interception rather than physical theft.

  • ✗

    Install a host-based firewall

    Why it's wrong here

    A host-based firewall filters inbound and outbound network traffic, so it cannot render files on a stolen disk unreadable. It is tempting because firewalls genuinely defend endpoints against network intrusion, and would be correct if the threat were unauthorised remote access rather than physical theft of the device.

  • ✓

    Enable full disk encryption

    Why this is correct

    Full disk encryption renders the entire drive unreadable without the decryption key, so a lost or stolen laptop's data at rest stays protected even if the disk is removed. It covers all files and the operating system, satisfying the requirement without relying on per-file user action.

  • ✗

    Implement strong password policies

    Why it's wrong here

    Password policies govern authentication credentials; an attacker with physical possession can remove the drive and read its contents without ever logging in. It is tempting because strong passwords genuinely restrict account access, and would be correct if the risk were credential compromise rather than offline access to the disk.

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.