Courseiva
Endpoint Security →mediumMultiple Choice

GSEC Endpoint Security Practice Question

When evaluating an endpoint's disk encryption, why is 'Pre-Boot Authentication' (PBA) considered a critical security component?

⚠ Common exam trap

Candidates often confuse PBA with Full Disk Encryption (FDE) generally, failing to realize that without PBA, the keys are loaded automatically at boot, leaving data vulnerable to cold-boot or memory attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It requires authentication before the encryption keys are released to memory.

PBA ensures that the encryption keys are not loaded into memory until the user provides the correct credentials at boot time. Without PBA, the encryption is transparent once the OS starts, meaning if the device is stolen while powered on or in sleep mode, an attacker could potentially access the data. PBA provides a strong gatekeeper that protects the data at rest even before the OS loads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It improves the speed of system startup and file indexing.

    Why it's wrong here

    PBA actually increases boot time because the user must provide authentication before the system can even load the operating system. It does not improve indexing or performance; rather, it introduces a necessary delay to ensure that unauthorized individuals cannot access the encrypted volumes on the drive.

  • ✗

    It ensures that the computer cannot be booted from an external drive.

    Why it's wrong here

    While PBA is a powerful control, it does not inherently disable external boot devices like USB drives. Disabling external boot must be configured separately in the BIOS or UEFI settings. PBA's primary function is to lock the encryption keys behind a password challenge, not to restrict physical port functionality.

  • ✓

    It requires authentication before the encryption keys are released to memory.

    Why this is correct

    Pre-Boot Authentication forces the user to input a secret before the decryption keys are loaded into RAM. This ensures that the data is truly protected against cold-boot attacks and unauthorized access if the machine is powered off, as the drive remains encrypted until that specific challenge is successfully met.

  • ✗

    It automatically syncs the encryption keys to a cloud-based backup.

    Why it's wrong here

    PBA is a local authentication mechanism, not a key management or backup service. Key escrow or recovery is handled by separate administrative processes, such as storing recovery keys in Active Directory or an enterprise disk encryption management server. It has nothing to do with cloud-based key synchronization directly.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.