A university's research department stores controlled unclassified research data on a Windows file server. The IT team wants to implement a defense in depth control that ensures only authorized users can access the data even if they have physical access to the server room. Which of the following controls best meets this requirement?
BitLocker encrypts the entire volume, so if the server or its disks are physically stolen or accessed from another OS, the data remains unreadable without the recovery key. This directly addresses the risk of unauthorized physical access, adding a layer that protects data at rest independent of user authentication.
Why this answer
The scenario requires a control that protects data even when an attacker has physical access to the server. Full disk encryption such as BitLocker encrypts the entire volume, rendering the data unreadable without the decryption key, regardless of user permissions or network controls. Thus, it provides a necessary layer in a defense in depth strategy for data at rest.
Exam trap
The trap here is assuming that logical access controls like NTFS permissions or firewalls can prevent physical access threats, when they only govern access through the operating system.