Courseiva
Security →mediumMultiple Select

FC0-U71 Data confidentiality Practice Question

A user wants to protect their laptop in case it is stolen. Which TWO of the following measures would help protect the confidentiality of the data?

⚠ Common exam trap

The question asks for two measures, and the correct answers are full disk encryption (B) and a strong user account password (D). Option E (screen lock) only helps when the laptop is on and locked, but does not protect data if the device is shut down. Candidates should not confuse screen lock with full data protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Full disk encryption

Full disk encryption (B) is correct because it encrypts the entire drive, so if the laptop is stolen the data remains unreadable without the decryption key, directly preserving confidentiality. A strong user account password (D) is correct because it prevents a thief from logging into the OS and accessing files under that account, adding an authentication barrier to the data. A BIOS password (A) only restricts firmware/startup access and can often be bypassed or reset, so it does not protect data confidentiality by itself. A VPN (C) protects data in transit on untrusted networks and does nothing for a stolen device. Screen lock with a password (E) only secures the current session and is trivially bypassed by removing the drive or booting another OS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A strong password set in the BIOS

    Why it's wrong here

    A BIOS password blocks firmware and boot-order changes but leaves the disk readable once removed and attached elsewhere, so it does not protect data confidentiality. It is tempting because it prevents booting or reconfiguring the machine, and would be correct for stopping unauthorised hardware or boot-device changes.

  • ✓

    Full disk encryption

    Why this is correct

    Full disk encryption renders the laptop's stored data unreadable without the decryption key, so a thief who removes the drive cannot access its contents. This directly preserves confidentiality of data at rest, satisfying the scenario's requirement should the device be stolen.

  • ✗

    Using a VPN when connected to public Wi-Fi

    Why it's wrong here

    A VPN encrypts data in transit over untrusted networks, so it does nothing once the laptop is stolen and its disk is read directly. It is the right control for protecting confidentiality on public Wi-Fi, not for data at rest.

  • ✓

    Using a strong password for the user account

    Why this is correct

    A strong account password prevents a thief from authenticating into the operating system and reaching the protected data. It enforces access control at the login layer, preserving confidentiality of the laptop's contents when the device is stolen, though it does not protect data at rest.

  • ✗

    Enabling the screen lock with a password

    Why it's wrong here

    A screen lock password only guards the running session; a thief can boot from external media or remove the drive and read the unencrypted data directly. It is tempting because it deters casual access, and it would be correct for preventing walk-up use of an unattended, powered-on laptop.

About these practice questions

One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on FC0-U71

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security administrator wants to protect data at rest on a laptop that may be lost or stolen. Which of the following is the BEST solution?

hard
  • A.Use a VPN when connecting to the internet
  • B.Install a host-based firewall
  • ✓ C.Enable full disk encryption
  • D.Implement strong password policies

Why C: Full disk encryption (FDE) protects data at rest by encrypting the entire volume, so if the laptop is lost or stolen the data is unreadable without the decryption key. This directly addresses the threat of physical device compromise, which is the scenario described.

Variation 2. A small business owner wants to protect customer data stored on laptops in case the devices are stolen. Which encryption method provides the best protection for the entire hard drive?

hard
  • A.HTTPS encryption for web traffic
  • B.File-level encryption on individual documents
  • C.A VPN when connecting to the internet
  • ✓ D.Full disk encryption

Why D: Full disk encryption (FDE) encrypts the entire storage volume — OS, applications, temp files, and user data — using a key protected by a TPM or pre-boot authentication, so a stolen laptop's drive is unreadable without the credential. Because it covers everything on the disk, it protects customer data regardless of which files or folders it lives in. This is the standard control for lost/stolen device scenarios.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.