What must be considered when planning Full Disk Encryption for laptops?
A security engineer is implementing FDE for all laptops in an organization. Which of the following are the most important for the engineer to consider as part of the planning process? (Choose two.)
Community Votes
100% of anonymous learners picked answer AB. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your understanding of FDE key management and hardware root of trust; the common trap is selecting public key management because FDE actually relies on symmetric encryption for bulk data, with asymmetric keys only used to protect the symmetric key.
When planning Full Disk Encryption (FDE) for an organization's laptops, key escrow and TPM presence are the two most critical considerations. Key escrow ensures recoverability of encryption keys, while a TPM provides hardware-based secure key storage and platform integrity verification.
Many candidates choose E (Public key management) because it sounds fundamental to cryptography, but FDE primarily uses symmetric encryption for data at rest, making public key management less directly relevant than key escrow and TPM presence.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Full Disk Encryption requires secure storage and recoverability of the symmetric encryption key that protects all data on the drive. A Trusted Platform Module (TPM) provides a hardware-based root of trust that securely stores and seals the FDE key to the specific platform, preventing unauthorized access even if the drive is removed. Key escrow ensures that if a user forgets their passphrase or the key is otherwise lost, the organization can still recover access to the encrypted data, which is essential for business continuity. Community comment [2] correctly notes that "finding a safe place for the encryption key is the most important," highlighting both TPM (hardware) and key escrow (software/policy) as complementary key management strategies.Why the Other Options Are Wrong
Digital signatures (C) are used for integrity and non-repudiation, not for bulk data encryption required by FDE. Data tokenization (D) replaces sensitive data elements with non-sensitive equivalents and is unrelated to full disk encryption scenarios. Public key management (E) is a tempting distractor because asymmetric cryptography is involved in protecting the symmetric key; however, as community comment [3] correctly points out, FDE primarily relies on symmetric encryption for the actual data, making public key infrastructure management less critical than ensuring the symmetric key is both securely stored (TPM) and recoverable (key escrow).Community Comment Notes
The community is overwhelmingly in agreement that A and B are correct, with 100 votes confirming this answer. Comment [4] provides valuable insight into why public key management, while "fundamental," is less important than understanding who holds the keys during the planning phase. Comment [6] expresses doubt but offers no alternative reasoning, while comment [9] suggests E without justification. The consensus clearly supports AB based on the practical requirements of FDE implementation.Official Reference
Exam Strategy
When a question asks about 'planning' for encryption, focus on key management and recovery rather than the cryptographic algorithms themselves. Always consider both the security aspect (where is the key stored?) and the business continuity aspect (what happens if the key is lost?) when evaluating FDE implementations.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →