SSCP Security Operations and Administration Practice Question
An organization wants to ensure that sensitive data on laptops is protected in case of loss or theft. Which control is MOST effective?
⚠ Common exam trap
A common mix-up: candidates choose remote wiping (D) because it seems proactive, but they overlook the critical requirement that the device must be online and powered on to execute the wipe, whereas full disk encryption protects data even if the device is never turned on again.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Full disk encryption
Full disk encryption (FDE) is the most effective control because it renders data unreadable at rest on the entire drive, including the operating system, swap files, and temporary files. Without the decryption key (e.g., a pre-boot PIN or TPM-bound key), an attacker cannot access any data even if the laptop is physically removed. This directly addresses the threat of data exposure from loss or theft, unlike controls that only limit access or track the device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Full disk encryption
Why this is correct
Full disk encryption renders the entire volume unreadable without the decryption key, so a stolen laptop's data stays confidential even if the drive is removed. This directly satisfies the loss-or-theft constraint, unlike file-level or database controls that leave unencrypted remnants exposed.
- ✗
Strong password policy
Why it's wrong here
A strong password policy only guards authentication; an attacker with the stolen laptop can remove the drive and read unencrypted data offline, bypassing it entirely. It is tempting because password policies are standard endpoint hardening, and they would be the right control against unauthorised interactive logon, not physical theft.
- ✗
Asset tracking software
Why it's wrong here
Asset tracking software records location and ownership but cannot prevent data disclosure once a device is in a thief's hands; it supports recovery and auditing, not confidentiality. It is tempting because tracking aids investigations after loss, and it would be correct where the requirement is inventory visibility or recovery of missing hardware.
- ✗
Remote wiping capability
Why it's wrong here
Remote wiping depends on the laptop being powered on and connected to the internet, so an offline stolen device retains its data indefinitely; full-disk encryption renders the drive unreadable regardless. Remote wipe is tempting because it addresses theft directly, and it would be correct for lost devices that reconnect to the management console.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.