FC0-U71 Security Practice Question
A small business owner wants to protect customer data stored on laptops in case the devices are stolen. Which encryption method provides the best protection for the entire hard drive?
⚠ Common exam trap
The trap is conflating in-transit encryption (HTTPS, VPN) with at-rest encryption — candidates see 'encryption' and pick a transport control when the scenario is about a stolen device and data on disk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Full disk encryption
Full disk encryption (FDE) encrypts the entire storage volume — OS, applications, temp files, and user data — using a key protected by a TPM or pre-boot authentication, so a stolen laptop's drive is unreadable without the credential. Because it covers everything on the disk, it protects customer data regardless of which files or folders it lives in. This is the standard control for lost/stolen device scenarios.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HTTPS encryption for web traffic
Why it's wrong here
HTTPS encrypts data in transit between browser and server, leaving data at rest on the stolen disk readable. It is tempting because it is encryption, but its scope is network traffic, not the drive; full-disk encryption such as BitLocker is the correct control here.
- ✗
File-level encryption on individual documents
Why it's wrong here
File-level encryption protects only the documents explicitly encrypted, leaving the rest of the drive, including temporary files and caches, exposed. It is tempting because it targets the customer documents directly, but whole-disk encryption is required to protect everything on a stolen laptop.
- ✗
A VPN when connecting to the internet
Why it's wrong here
A VPN encrypts data in transit over the internet, providing no protection for data at rest once the laptop is stolen. It is tempting because VPNs are a familiar encryption tool, but their scope is network communication, not the physical drive.
- ✓
Full disk encryption
Why this is correct
Full disk encryption protects the entire drive, including the operating system, applications and all stored files, so data remains unreadable if a laptop is stolen. It satisfies the requirement to safeguard customer data on lost devices.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.