Courseiva

GSEC Security Frameworks and CIS Controls Practice Question

A healthcare provider is implementing CIS Control 3: Data Protection. They must ensure that data at rest is encrypted according to the safeguards. Which of the following activities directly satisfies the requirements of CIS Control 3 for data at rest?

⚠ Common exam trap

Many candidates confuse data-in-transit encryption with data-at-rest encryption, and assuming that any security measure involving data satisfies the control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enabling full-disk encryption on all endpoints and servers that store protected health information.

Full-disk encryption directly satisfies the CIS Control 3 requirement to encrypt data at rest on endpoints and servers. It ensures that if a device is lost or stolen, the stored data remains unreadable. Other options address data in transit, monitoring, or physical security, which are important but do not meet the specific encryption-at-rest mandate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enabling full-disk encryption on all endpoints and servers that store protected health information.

    Why this is correct

    CIS Control 3 explicitly requires encryption of data at rest on end-user devices and servers. Full-disk encryption protects data if a device is lost or stolen. This directly addresses the safeguard for data at rest, making it the correct action.

  • ✗

    Deploying a data loss prevention (DLP) solution to monitor outbound email containing patient data.

    Why it's wrong here

    DLP helps prevent unauthorized exfiltration of data, but it does not encrypt data at rest. CIS Control 3 requires encryption of stored data, not just monitoring of data flows. DLP is a complementary control but does not fulfill the encryption safeguard.

  • ✗

    Configuring database backup files to be stored in a separate physical location with access controls.

    Why it's wrong here

    Physical separation and access controls protect backups from unauthorized access, but they do not encrypt the data. CIS Control 3 requires that data at rest be encrypted, regardless of location. Backup files containing PHI must also be encrypted to meet the safeguard.

  • ✗

    Implementing TLS 1.2 for all web traffic to and from the electronic health record system.

    Why it's wrong here

    TLS 1.2 encrypts data in transit, not at rest. While important for protecting data during transmission, it does not satisfy the requirement for encrypting stored data. CIS Control 3 distinguishes between data in transit and data at rest, and this action only covers the former.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.