Encryption at rest primarily protects the confidentiality of stored information when an unauthorized party obtains physical or logical access to the storage medium. This is particularly important for laptops because portable devices can be lost or stolen, giving an attacker possession of the disk outside the organization's normal network and endpoint protections.
NIST guidance on storage encryption specifically addresses laptops and other end-user devices and explains that storage encryption combines encryption and authentication to restrict unauthorized access to stored information. NIST further notes that threats involving lost or stolen end-user devices can expose information to unauthorized parties.
Encryption does not inherently prevent an authenticated and authorized user from copying information while the system is unlocked; data loss prevention controls are more directly suited to that objective. Regulatory requirements may mandate encryption in some environments, but compliance is an external requirement rather than the fundamental security reason encryption at rest exists. Option D confuses confidentiality with integrity and network protection. Encryption of data stored on a laptop is not primarily intended to validate whether network data has been modified.
The examination concept is the CIA triad: encryption primarily supports confidentiality , especially when physical possession of the storage device is lost.
Study Guide Reference: Security Operations → Data Protection → Encryption at Rest → Full-Disk Encryption → Confidentiality → Lost/Stolen Endpoint Protection.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit