FC0-U71 Security Practice Question
A security administrator wants to protect data at rest on a laptop that may be lost or stolen. Which of the following is the BEST solution?
⚠ Common exam trap
FC0-U71 often tests the distinction between data-at-rest and data-in-transit controls — candidates pick VPN or firewall when the scenario is specifically about a lost/stolen device.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable full disk encryption
Full disk encryption (FDE) protects data at rest by encrypting the entire volume, so if the laptop is lost or stolen the data is unreadable without the decryption key. This directly addresses the threat of physical device compromise, which is the scenario described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a VPN when connecting to the internet
Why it's wrong here
A VPN encrypts data in transit, leaving the laptop's stored files readable once the disk is removed or the device booted. It tempts because VPNs are the standard answer for protecting data on untrusted networks, which is the correct choice when the risk is interception rather than physical theft.
- ✗
Install a host-based firewall
Why it's wrong here
A host-based firewall filters inbound and outbound network traffic, so it cannot render files on a stolen disk unreadable. It is tempting because firewalls genuinely defend endpoints against network intrusion, and would be correct if the threat were unauthorised remote access rather than physical theft of the device.
- ✓
Enable full disk encryption
Why this is correct
Full disk encryption renders the entire drive unreadable without the decryption key, so a lost or stolen laptop's data at rest stays protected even if the disk is removed. It covers all files and the operating system, satisfying the requirement without relying on per-file user action.
- ✗
Implement strong password policies
Why it's wrong here
Password policies govern authentication credentials; an attacker with physical possession can remove the drive and read its contents without ever logging in. It is tempting because strong passwords genuinely restrict account access, and would be correct if the risk were credential compromise rather than offline access to the disk.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.