Which solution protects laptop data if the device is stolen?
A security administrator is working to secure company data on corporate laptops in case the laptops are stolen. Which of the following solutions should the administrator consider?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam is testing your ability to distinguish between technologies that protect data at rest (disk encryption) versus other security controls. The trap is confusing remote wipe with disk encryption—remote wipe deletes data after a device is lost, while disk encryption protects the data before and after theft.
This Security+ question tests the best solution for protecting data on stolen laptops. The community overwhelmingly agrees that disk encryption is the correct answer, as it encrypts data at rest and prevents unauthorized access to files on a lost device.
A common mistake is choosing Data loss prevention (DLP) because its name suggests preventing data loss. However, DLP is designed to monitor and block data exfiltration over networks, not to protect data on a stolen laptop. Another trap is selecting boot security, which protects the boot process but does not encrypt the entire disk.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Disk encryption (A) is the correct answer because it directly secures data on the hard drive by converting it into an unreadable format without the proper key. If a laptop is stolen, the encrypted data remains inaccessible to the thief, ensuring confidentiality of company information. This aligns with standard data-at-rest protection requirements for mobile devices.Why the Other Options Are Wrong
Data loss prevention (B) is incorrect because DLP focuses on preventing unauthorized transmission of data, not securing data stored on a device. Operating system hardening (C) strengthens system configurations but does not encrypt data, making it ineffective if the physical drive is removed. Boot security (D) ensures that the device launches only trusted OS components but leaves stored data vulnerable once the drive is accessed from another system.Community Comment Notes
One commenter (likes=2) insightfully noted that this question is easy when disk encryption is the only data-focused option, but adding remote wipe would create a split—highlighting the need to understand the difference between encryption and wiping. Another comment (likes=3) simply affirmed the answer as A, and a third (likes=1) echoed disk encryption. These comments reinforce that the official consensus is clear, but exam takers should be ready for variants that include remote wipe as a distractor.Official Reference
Exam Strategy
When you see a scenario involving stolen or lost devices, immediately think about data at rest. Focus on controls that protect the confidentiality of stored data—disk encryption is the standard answer. Also, mentally distinguish between encryption (rendering data unusable) and remote wipe (erasing data after the fact); both are valid but the question wording will guide you to the best fit.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →