問題文
A laptop fleet must have its data unreadable if a device is stolen while powered off. The requirement does not include protecting data from a logged-in user. Which measure fits?
選択肢
- Filesystem permissions set so that only the owner can read each file, because permissions are enforced by the kernel and therefore remain in effect when the disk is removed and attached to another machine.
- Per-file encryption managed by each application, since applications know best which files are sensitive, and the files chosen that way stay encrypted while the laptop is powered off.
- Block-level encryption of the volume, unlocked with a passphrase at boot, which leaves the data unreadable while the device is powered off.
- A screen lock with a short timeout, which prevents access to the running system.