PK0-005 Practice Question: Basics of IT Infrastructure and IT Project Management
A project manager is overseeing the deployment of a new file server that will store sensitive financial data. The project sponsor requires that data at rest be encrypted to comply with industry regulations. The project manager must choose an encryption method that provides strong security without significantly impacting performance. Which of the following should the project manager recommend?
⚠ Common exam trap
Candidates often confuse data-in-transit encryption methods like IPsec or SSL/TLS with data-at-rest encryption, which requires full-disk or file-level encryption technologies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker Drive Encryption
BitLocker Drive Encryption is designed to encrypt entire volumes, protecting data at rest even if the physical disk is removed or stolen. It uses strong AES encryption and integrates with TPM for key protection, offering a balance of security and performance. Other options either encrypt data in transit or control access without encryption, failing to meet the requirement for data-at-rest encryption to comply with regulations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IPsec transport mode
Why it's wrong here
IPsec transport mode encrypts data in transit between hosts, not data at rest on the server's disks. While it protects data as it travels over the network, it does not encrypt files stored on the file server. The requirement is specifically for data at rest, so IPsec transport mode does not satisfy the compliance need. Additionally, IPsec can add overhead and complexity to network communications.
- ✗
File-level permissions
Why it's wrong here
File-level permissions control access to files based on user or group identity but do not encrypt the data. If someone bypasses permissions by accessing the physical disk or using administrative privileges, the data is readable. Permissions are an access control mechanism, not an encryption method, and therefore do not satisfy the requirement for encrypting data at rest to meet regulatory standards.
- ✓
BitLocker Drive Encryption
Why this is correct
BitLocker provides full-disk encryption for data at rest, using AES encryption with key lengths up to 256 bits. It integrates with hardware TPM for secure key storage and has minimal performance overhead on modern hardware. It meets regulatory requirements for encrypting sensitive data at rest and is suitable for file servers. BitLocker also supports network unlock and can be managed via Group Policy, making it appropriate for enterprise deployments.
- ✗
SSL/TLS certificates
Why it's wrong here
SSL/TLS certificates are used to encrypt data in transit, such as HTTPS traffic, and to authenticate servers. They do not encrypt data stored on disk. While important for securing web communications, they do not address the requirement for data-at-rest encryption. Implementing SSL/TLS would not meet the regulatory compliance for protecting stored financial data, leaving the files vulnerable if the physical disks are compromised.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 954 original PK0-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PK0-005 exam.