easyMultiple Choice
SSCP Practice Question: Requires that all laptops used by employees be…
An organization requires that all laptops used by employees be encrypted. Which type of encryption should be used to protect the entire hard drive?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Full disk encryption (FDE)
Full disk encryption (FDE) encrypts the entire hard drive, including the operating system and all files, providing the strongest protection for data at rest on lost or stolen laptops. File-level encryption only encrypts individual files, leaving metadata and other files exposed. Folder-level encryption is similar but at the folder level. Transport encryption (TLS) protects data in transit, not at rest. Application-level encryption encrypts data within a specific application, not the entire drive. Therefore, full disk encryption (Option B) is the correct choice for protecting the entire hard drive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
File-level encryption
Why it's wrong here
File-level encryption protects individual files or folders, leaving the operating system, swap files and unselected data readable if the drive is removed. It is tempting because it lets administrators encrypt only sensitive documents, which suits selective data-protection policies rather than the stem's whole-disk requirement.
- ✓
Full disk encryption (FDE)
Why this is correct
Full disk encryption operates below the file system, encrypting every sector of the drive including the OS, swap and temporary files. This satisfies the requirement that the entire hard drive be protected, since data at rest remains unreadable if the laptop is lost or stolen.
- ✗
Transport encryption (TLS)
Why it's wrong here
TLS secures data in transit between endpoints, not data at rest on the drive, so a stolen laptop's contents remain readable. It is tempting because transport encryption is genuinely required for protecting network traffic, which is a separate control from full-disk encryption.
- ✗
Application-level encryption
Why it's wrong here
Application-level encryption protects data only within that application's own handling, leaving the rest of the disk unencrypted. It is tempting because it targets sensitive fields precisely, and would be correct where a single application must encrypt specific data regardless of storage, not for full-disk protection.
- ✗
Folder-level encryption
Why it's wrong here
Folder-level encryption protects only files within designated folders, leaving the operating system, swap files and other directories in plaintext. It is tempting because it is simple to apply per-directory, and would be correct where only specific sensitive document sets need protection rather than the whole drive.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.