SY0-701 Security Architecture Practice Question
A hospital is deploying a new medical imaging system that stores patient data. The system must ensure that data remains confidential even if the physical storage media is stolen. Which of the following controls should be implemented?
⚠ Common exam trap
Candidates often confuse access controls or network segmentation with data-at-rest protection, which are ineffective if the physical drive is stolen.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Full-disk encryption (FDE) on the storage media.
The correct answer is full-disk encryption. It is the only control that ensures data confidentiality if the physical storage media is stolen, because the data is encrypted and inaccessible without the key. Other options address access control, network security, or user awareness, none of which protect data at rest against physical theft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Full-disk encryption (FDE) on the storage media.
Why this is correct
Full-disk encryption encrypts all data on the storage media, rendering it unreadable without the decryption key. If the physical media is stolen, the data remains confidential because the thief cannot access it without the key. This directly addresses the requirement to protect data at rest in the event of physical theft, making it the appropriate control.
- ✗
Regular security awareness training for staff.
Why it's wrong here
Security awareness training helps reduce human error and social engineering risks, but it cannot prevent the physical theft of storage media or protect the data if the media is stolen. It is a preventive measure for user behavior, not a technical control for data-at-rest confidentiality. Therefore, it does not meet the scenario's requirement.
- ✗
Network segmentation using VLANs.
Why it's wrong here
Network segmentation isolates traffic to reduce attack surface and limit lateral movement, but it does not protect data stored on physical media. If the storage media is stolen, segmentation is irrelevant because the attacker has direct access to the drive. Thus, it does not satisfy the confidentiality requirement for stolen media.
- ✗
File-level access controls based on user roles.
Why it's wrong here
File-level access controls restrict who can read or modify files when the system is running and the user is authenticated. However, if the physical storage media is stolen, an attacker could bypass these controls by attaching the drive to another system. Therefore, access controls alone do not protect data at rest against physical theft, failing the requirement.
Go deeper
Related to this question
Learn chapter
Cloud Access Security Broker (CASB)
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Terminal Access Controller Access Control System Plus
TACACS+ is a network security protocol that separates authentication, authorization, and accounting to control who can access network devices and what they can do.
About these practice questions
One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.