What must be considered when planning Full Disk Encryption for laptops?

A security engineer is implementing FDE for all laptops in an organization. Which of the following are the most important for the engineer to consider as part of the planning process? (Choose two.)

  1. Key escrow Source Reference Answer
  2. TPM presence Source Reference Answer
  3. Digital signatures
  4. Data tokenization
  5. Public key management

Community Votes

AB
100%

100% of anonymous learners picked answer AB. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your understanding of FDE key management and hardware root of trust; the common trap is selecting public key management because FDE actually relies on symmetric encryption for bulk data, with asymmetric keys only used to protect the symmetric key.

When planning Full Disk Encryption (FDE) for an organization's laptops, key escrow and TPM presence are the two most critical considerations. Key escrow ensures recoverability of encryption keys, while a TPM provides hardware-based secure key storage and platform integrity verification.

Many candidates choose E (Public key management) because it sounds fundamental to cryptography, but FDE primarily uses symmetric encryption for data at rest, making public key management less directly relevant than key escrow and TPM presence.

Community Discussion (9 comments)

Etc_Shadow28000 👍 10 Selected: AB
A. Key escrow B. TPM presence - Key escrow: This is important to ensure that encryption keys can be recovered in case they are lost or forgotten. It is a crucial consideration for Full Disk Encryption (FDE) to maintain access to data even if issues arise with the primary encryption keys. - TPM presence: Trusted Platform Module (TPM) is a hardware-based security feature that can store encryption keys securely. Ensuring the presence of TPM on laptops enhances the security of FDE by protecting the encryption keys from being accessed or tampered with. Therefore, the most important considerations for the security engineer are: A. Key escrow B. TPM presence
9149f41 👍 2 Selected: AB
In the planning process, finding a safe place for the encryption key is the most important. Key escrow is a software-based, and TPM is a hardware-based system where we can keep the encryption key for future decryptions. Other options are not relevant in the planning process of FDE.
3dk1 👍 2
AB for sure. Here is why E is not one of them (ai generated, but I agree with the answer) Public key management is essential in many cryptographic processes, but it's not as directly relevant to Full Disk Encryption (FDE) for the following reasons: FDE primarily uses symmetric encryption: Most FDE solutions rely on symmetric encryption, where the same key is used to both encrypt and decrypt the data. This differs from public key infrastructure (PKI), which involves asymmetric encryption, where a public key encrypts and a private key decrypts. While PKI is critical in other areas (like securing communications, emails, or verifying identities), it's not central to how FDE typically functions. Public key management is more relevant for data in transit: PKI and public key management are often used for securing data in transit (e.g., SSL/TLS for web traffic) or ensuring non-repudiation (via digital signatures). FDE is focused on securing data at rest, where symmetric keys (often stored in TPM) are used for encryption, not public/private key pairs.
dbrowndiver 👍 1 Selected: AB
In this scenario, A. Key escrow and B. TPM presence are the most important considerations for implementing Full Disk Encryption (FDE) on laptops. These elements ensure that encryption keys are securely managed and stored, providing both data security and recoverability in case of lost keys, and that hardware-based security is used to protect against unauthorized access.
Shaman73 👍 1 Selected: AB
A. Key escrow B. TPM presence
shady23 👍 1 Selected: AB
A. Key escrow B. TPM presence
Fazliddin4515 👍 1
I think E is also correct one
Yoez 👍 1
I don't think so that are the correct answers.
e5c1bb5 👍 2 Selected: AB
this one is tough because public key management is fundamental to full disc ecryption. that being said, key escrow is arguably more important for the following reasons. public key's are used to encrypt the data and the PRIVATE key is used to decrypt the data. once the data is encrypted, i would argue who holds the keys (another department or another 3rd party) is more important than establishing the encryption (because thats kind of the easy part). TPM presence is even more fundamental to FDE than the public key is because without it, you cant even consider FDE. those are my thoughts going with AB for now. please share your thoughts. if i didnt pick AB i'd go BE

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Full Disk Encryption requires secure storage and recoverability of the symmetric encryption key that protects all data on the drive. A Trusted Platform Module (TPM) provides a hardware-based root of trust that securely stores and seals the FDE key to the specific platform, preventing unauthorized access even if the drive is removed. Key escrow ensures that if a user forgets their passphrase or the key is otherwise lost, the organization can still recover access to the encrypted data, which is essential for business continuity. Community comment [2] correctly notes that "finding a safe place for the encryption key is the most important," highlighting both TPM (hardware) and key escrow (software/policy) as complementary key management strategies.

Why the Other Options Are Wrong

Digital signatures (C) are used for integrity and non-repudiation, not for bulk data encryption required by FDE. Data tokenization (D) replaces sensitive data elements with non-sensitive equivalents and is unrelated to full disk encryption scenarios. Public key management (E) is a tempting distractor because asymmetric cryptography is involved in protecting the symmetric key; however, as community comment [3] correctly points out, FDE primarily relies on symmetric encryption for the actual data, making public key infrastructure management less critical than ensuring the symmetric key is both securely stored (TPM) and recoverable (key escrow).

Community Comment Notes

The community is overwhelmingly in agreement that A and B are correct, with 100 votes confirming this answer. Comment [4] provides valuable insight into why public key management, while "fundamental," is less important than understanding who holds the keys during the planning phase. Comment [6] expresses doubt but offers no alternative reasoning, while comment [9] suggests E without justification. The consensus clearly supports AB based on the practical requirements of FDE implementation.

Official Reference

Exam Strategy

When a question asks about 'planning' for encryption, focus on key management and recovery rather than the cryptographic algorithms themselves. Always consider both the security aspect (where is the key stored?) and the business continuity aspect (what happens if the key is lost?) when evaluating FDE implementations.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide