A small accounting firm wants to ensure that if a laptop is lost, the data on its full-disk-encrypted drive cannot be recovered by an attacker who removes the drive and mounts it elsewhere. Which additional control is MOST important to meet this goal?
Full-disk encryption with a key protector that requires a secret known only to the user means the volume encryption key cannot be unwrapped without that secret. An attacker who extracts the drive still lacks the input needed to decrypt, so pre-boot authentication is the control that converts encryption at rest into meaningful protection for a lost device.
Why this answer
Encryption at rest only protects a lost device when the key is protected by a secret the attacker does not possess. Requiring pre-boot authentication with a PIN or password ensures the volume master key cannot be unwrapped offline, whereas screen locks, EDR, and backups operate on different threat models and cannot prevent offline decryption of a removed drive.
Exam trap
The trap here is assuming that enabling full-disk encryption by itself protects a stolen drive, when the protection depends entirely on how the encryption key is protected.