Courseiva

PK0-005 Practice Question: Basics of IT Infrastructure and IT Project Management

A project manager is overseeing the deployment of a new file server that will store sensitive financial data. The project sponsor requires that data at rest be encrypted to comply with industry regulations. The project manager must choose an encryption method that provides strong security without significantly impacting performance. Which of the following should the project manager recommend?

⚠ Common exam trap

Candidates often confuse data-in-transit encryption methods like IPsec or SSL/TLS with data-at-rest encryption, which requires full-disk or file-level encryption technologies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

BitLocker Drive Encryption

BitLocker Drive Encryption is designed to encrypt entire volumes, protecting data at rest even if the physical disk is removed or stolen. It uses strong AES encryption and integrates with TPM for key protection, offering a balance of security and performance. Other options either encrypt data in transit or control access without encryption, failing to meet the requirement for data-at-rest encryption to comply with regulations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IPsec transport mode

    Why it's wrong here

    IPsec transport mode encrypts data in transit between hosts, not data at rest on the server's disks. While it protects data as it travels over the network, it does not encrypt files stored on the file server. The requirement is specifically for data at rest, so IPsec transport mode does not satisfy the compliance need. Additionally, IPsec can add overhead and complexity to network communications.

  • ✗

    File-level permissions

    Why it's wrong here

    File-level permissions control access to files based on user or group identity but do not encrypt the data. If someone bypasses permissions by accessing the physical disk or using administrative privileges, the data is readable. Permissions are an access control mechanism, not an encryption method, and therefore do not satisfy the requirement for encrypting data at rest to meet regulatory standards.

  • ✓

    BitLocker Drive Encryption

    Why this is correct

    BitLocker provides full-disk encryption for data at rest, using AES encryption with key lengths up to 256 bits. It integrates with hardware TPM for secure key storage and has minimal performance overhead on modern hardware. It meets regulatory requirements for encrypting sensitive data at rest and is suitable for file servers. BitLocker also supports network unlock and can be managed via Group Policy, making it appropriate for enterprise deployments.

  • ✗

    SSL/TLS certificates

    Why it's wrong here

    SSL/TLS certificates are used to encrypt data in transit, such as HTTPS traffic, and to authenticate servers. They do not encrypt data stored on disk. While important for securing web communications, they do not address the requirement for data-at-rest encryption. Implementing SSL/TLS would not meet the regulatory compliance for protecting stored financial data, leaving the files vulnerable if the physical disks are compromised.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 954 original PK0-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PK0-005 exam.