Which data protection strategy prevents loss on stolen laptops?

Data Security

A bank insists all of its vendors must prevent data loss on stolen laptops. Which of the following strategies is the bank requiring?

  1. Encryption at rest Source Reference Answer
  2. Masking
  3. Data classification
  4. Permission restrictions

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the ability to map a physical security threat (stolen hardware) to its corresponding logical control (encryption), specifically distinguishing between data in motion, at rest, and in use.

Encryption at rest is the required strategy to protect data stored on physical devices like laptops from unauthorized access if they are stolen. The community consensus confirms this as the standard control for mitigating physical theft risks.

Community Discussion (3 comments)

dbrowndiver 👍 6 Selected: A
When a laptop is stolen, encryption at rest ensures that the data remains secure and inaccessible to the thief, as they would need the decryption key to access the files. Data Protection: Encryption at rest provides a robust layer of security for sensitive data, making it a common requirement for organizations handling confidential information. The primary concern with stolen laptops is unauthorized access to the data stored on them. Encryption at rest is the most effective way to prevent data loss in this scenario, as it keeps the data secure even if the device falls into the wrong hands.
9149f41 👍 1 Selected: A
When the device is stolen, the data will always be in rest. So the answer is easy: Encyption at rest.
Shaman73 👍 3
A. Encryption at rest

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Encryption at rest protects data stored on non-volatile media, such as hard drives or SSDs in laptops. If a laptop is stolen, the thief cannot read the data without the decryption key, effectively preventing data loss or exposure. This aligns with regulatory requirements and best practices for handling sensitive information on portable devices.

Why the Other Options Are Wrong

Masking (B) hides data values but does not secure the underlying storage against physical theft. Data classification (C) is an administrative process to categorize data sensitivity but offers no technical protection if the device is lost. Permission restrictions (D) rely on the operating system being accessible; if the drive is removed or booted from external media, these controls can often be bypassed.

Community Comment Notes

Users unanimously agreed on Encryption at rest because the scenario explicitly mentions 'stolen laptops,' implying the data is physically offline. Comments highlight that encryption ensures data remains inaccessible even if the hardware falls into malicious hands, making it the most robust defense for this specific threat vector.

Official Reference

Exam Strategy

Identify the state of the data (in use, in transit, or at rest) based on keywords like 'stolen,' 'transferred,' or 'processing.' For physical theft scenarios involving storage media, always prioritize encryption at rest over access controls.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide