A healthcare provider is implementing CIS Control 3: Data Protection. They must ensure that data at rest is encrypted according to the safeguards. Which of the following activities directly satisfies the requirements of CIS Control 3 for data at rest?
CIS Control 3 explicitly requires encryption of data at rest on end-user devices and servers. Full-disk encryption protects data if a device is lost or stolen. This directly addresses the safeguard for data at rest, making it the correct action.
Why this answer
Full-disk encryption directly satisfies the CIS Control 3 requirement to encrypt data at rest on endpoints and servers. It ensures that if a device is lost or stolen, the stored data remains unreadable. Other options address data in transit, monitoring, or physical security, which are important but do not meet the specific encryption-at-rest mandate.
Exam trap
The trap here is confusing data-in-transit encryption with data-at-rest encryption, and assuming that any security measure involving data satisfies the control.