SSCP Systems and Application Security Practice Question
A healthcare provider must ensure that stored patient records remain unreadable if an attacker steals the physical disk from a database server. The server runs a mainstream Linux distribution and the requirement applies to the entire volume, not just individual files. Which control best meets this requirement?
⚠ Common exam trap
Watch out — candidates often confuse access control mechanisms like file permissions or SELinux with data-at-rest encryption, which are different layers solving different threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Full disk encryption with LUKS on the data volume
Whole-volume encryption converts all data on the block device into ciphertext at rest and requires a key to mount it. When the disk is stolen, the ciphertext is useless without that key, which directly satisfies the requirement to keep records unreadable after physical theft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Full disk encryption with LUKS on the data volume
Why this is correct
LUKS encrypts the block device itself, so every sector written to the volume is ciphertext while at rest. If the disk is removed and mounted elsewhere, the data is unreadable without the passphrase or key file. This satisfies whole-volume confidentiality for a stolen physical disk.
- ✗
Enforcing strict file permissions on the data directory
Why it's wrong here
POSIX permissions control which local users can read files while the operating system is running, but they offer no protection once the disk is physically removed and attached to another machine. An attacker with the disk can bypass the file system's access checks entirely, so this does not meet the stated threat.
- ✗
Enabling SELinux in enforcing mode on the server
Why it's wrong here
SELinux is a mandatory access control framework that confines running processes; it does not encrypt data at rest. An attacker who removes the disk reads raw blocks without ever invoking SELinux policy checks. It addresses runtime confinement, not physical theft of storage media.
- ✗
Per-file encryption performed by the database engine
Why it's wrong here
Database-level encryption can protect specific columns or tablespaces, but it leaves database metadata, logs, and temporary files unprotected and depends on the DBMS being configured correctly for every object. The requirement covers the entire volume, so a partial, application-layer approach leaves data exposed.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.