exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 289 discussion

Actual exam question from CompTIA's SY0-601
Question #: 289
Topic #: 1
[All SY0-601 Questions]

An organization with a low tolerance for user inconvenience wants to protect laptop hard drives against loss or data theft. Which of the following would be the MOST acceptable?

  • A. SED
  • B. HSM
  • C. DLP
  • D. TPM
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
FMMIR
Highly Voted 2 years, 6 months ago
Selected Answer: A
A. SED (self-encrypting drive) would be the most acceptable option for an organization with a low tolerance for user inconvenience that wants to protect laptop hard drives against loss or data theft. SEDs are hardware-based encryption devices that automatically encrypt data on a hard drive without requiring any additional input or configuration from the user. This means that the user does not have to perform any additional steps to encrypt their data, which can help to prevent data loss or theft. By contrast, other options like HSM (hardware security module), DLP (data loss prevention), and TPM (trusted platform module) may require more user involvement and may not be as convenient for users.
upvoted 32 times
...
okay123
Highly Voted 2 years, 6 months ago
Selected Answer: D
I think i will go with D because the key words "user inconvenice." A TPM isn’t something you have to think about much. Your computer either has a TPM or it doesn’t — and modern computers generally will. An SED drive is an external drive connected to your laptop, that's a whole other situation. " TPM is arguably more of a convenience feature. Storing the encryption keys in hardware allows a computer to automatically decrypt the drive, or decrypt it with a simple password. It’s more secure than simply storing that key on the disk, as an attacker can’t simply remove the disk and insert it into another computer. It’s tied to that specific hardware." https://www.howtogeek.com/237232/what-is-a-tpm-and-why-does-windows-need-one-for-disk-encryption/ It was literally made to be convenient!
upvoted 10 times
Alcpt
1 year, 2 months ago
TPM alone does not encrypt data; it manages keys and provides a secure environment. It facilitates disk encryption software like SED. Answer is A
upvoted 1 times
...
kigikik881
1 year, 8 months ago
But it's just module which stores and manages security keys, it doesn't do anything itself
upvoted 2 times
...
Teleco0997
1 year, 7 months ago
SED means Self Encrypting Device there is no external drive anywhere
upvoted 3 times
Teleco0997
1 year, 7 months ago
device or drive, both are used, why i meant is: it is the storage device itself (e.g., a hard drive or solid-state drive) that incorporates built-in hardware for encryption, not an external device that you attach to another storage device for encryption
upvoted 1 times
...
...
...
david124
Most Recent 1 year, 5 months ago
Selected Answer: A
TPM is for cryptographic processing and key storage. SED is a Self Encrypting Drive in case it gets stolen
upvoted 2 times
...
Grumpy_Old_Coot
1 year, 5 months ago
Selected Answer: A
SED. The question is specifically talking about hard drives here. TPM handles all sorts of keys, not just bitlocker.
upvoted 1 times
...
shaneo007
1 year, 5 months ago
TPM must be activated/enabled to work with Bitlocker by the user as well as other OS system encryption software. SED auto encrypts and decrypts data without user intervention. SED would be the most convenient
upvoted 1 times
...
Soleandheel
1 year, 7 months ago
SED is the most accurate answer here.
upvoted 1 times
...
ComPCertOn
1 year, 7 months ago
Selected Answer: A
I’d go with SED
upvoted 1 times
...
Cyberjerry
1 year, 8 months ago
Selected Answer: A
Self-Encrypting Drives (SEDs) offer hardware-based encryption for data at rest. They are built into the hard drive itself and automatically encrypt all data written to the drive.
upvoted 2 times
...
Afel_Null
1 year, 8 months ago
Selected Answer: C
Data Loss Prevention is a complex mechanism meant to protect against data theft, exfiltration or unruly publication.
upvoted 1 times
...
malibi
1 year, 9 months ago
Selected Answer: A
SED encrypts harddrive, while hsm and tpm stores and manages keys/ secrets!
upvoted 3 times
...
gho5tface
1 year, 10 months ago
Selected Answer: A
SED - Anything written to the drive is automatically encrypted. Encryption that is built into the hardware of the drive itself.
upvoted 1 times
...
Abdul2107
1 year, 11 months ago
Selected Answer: A
A. SED Only SED (Self-encrypting drive) requires no or minimum user intervention/inconvenience.
upvoted 1 times
...
ApplebeesWaiter1122
1 year, 12 months ago
Selected Answer: A
SEDs are hard drives that have built-in hardware encryption capabilities. They automatically encrypt data as it is written to the drive and decrypt it as it is read, transparently to the user. This means that even if the hard drive is removed or stolen, the data remains encrypted and is not accessible without the proper authentication credentials. By using SEDs, the organization can ensure that data stored on laptops is protected at all times, without requiring additional user actions or impacting their workflow. It provides a strong security measure against data loss or theft while minimizing inconvenience for the users.
upvoted 4 times
...
Navigator
2 years ago
Selected Answer: A
After further research, I believe the right option is A. Please note.
upvoted 2 times
...
Navigator
2 years ago
Selected Answer: D
I choose D because of the explanation below. What is SED vs full-disk encryption? Full-disk encryption (FDE) and self-encrypting drives (SED) encrypt data as it is written to the disk and decrypt data as it is read off the disk. FDE makes sense for laptops, which are highly susceptible to loss or theft. But FDE isn't suitable for the most common risks faced in data center and cloud environments.
upvoted 1 times
...
fouserd
2 years, 2 months ago
Selected Answer: A
The most acceptable option to protect laptop hard drives against loss or data theft is SED. A self-encrypting drive (SED) automatically encrypts all data written to the drive and decrypts all data read from the drive. This provides protection against data theft if the laptop is lost or stolen.
upvoted 1 times
...
DWISE1
2 years, 3 months ago
The OPAL storage specification is the industry standard for self-encrypting drives. This is a hardware solution, and typically outperform software-based alternatives. They don't have the same vulnerabilities as software and therefore are more secure. SEDs are Solid State Drives (SSDs) and are purchased already set to encrypt data at rest. The encryption keys are stored on the hard drive controller. They are immune to a cold boot attack and are compatible with all operating systems
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...