GSEC Security Frameworks and CIS Controls Practice Question
A healthcare provider is implementing CIS Control 3: Data Protection. They must ensure that data at rest is encrypted according to the safeguards. Which of the following activities directly satisfies the requirements of CIS Control 3 for data at rest?
⚠ Common exam trap
Many candidates confuse data-in-transit encryption with data-at-rest encryption, and assuming that any security measure involving data satisfies the control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enabling full-disk encryption on all endpoints and servers that store protected health information.
Full-disk encryption directly satisfies the CIS Control 3 requirement to encrypt data at rest on endpoints and servers. It ensures that if a device is lost or stolen, the stored data remains unreadable. Other options address data in transit, monitoring, or physical security, which are important but do not meet the specific encryption-at-rest mandate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enabling full-disk encryption on all endpoints and servers that store protected health information.
Why this is correct
CIS Control 3 explicitly requires encryption of data at rest on end-user devices and servers. Full-disk encryption protects data if a device is lost or stolen. This directly addresses the safeguard for data at rest, making it the correct action.
- ✗
Deploying a data loss prevention (DLP) solution to monitor outbound email containing patient data.
Why it's wrong here
DLP helps prevent unauthorized exfiltration of data, but it does not encrypt data at rest. CIS Control 3 requires encryption of stored data, not just monitoring of data flows. DLP is a complementary control but does not fulfill the encryption safeguard.
- ✗
Configuring database backup files to be stored in a separate physical location with access controls.
Why it's wrong here
Physical separation and access controls protect backups from unauthorized access, but they do not encrypt the data. CIS Control 3 requires that data at rest be encrypted, regardless of location. Backup files containing PHI must also be encrypted to meet the safeguard.
- ✗
Implementing TLS 1.2 for all web traffic to and from the electronic health record system.
Why it's wrong here
TLS 1.2 encrypts data in transit, not at rest. While important for protecting data during transmission, it does not satisfy the requirement for encrypting stored data. CIS Control 3 distinguishes between data in transit and data at rest, and this action only covers the former.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.