Which of the following is an example of a vulnerability of full-disk encryption (FDE)?
Correct Answer: A
Full-disk encryption (FDE) is a security technique that encrypts the entire hard drive of a device or system, protecting the data at rest from unauthorized access, disclosure, or modification. However, FDE has a vulnerability that data at rest has been compromised when the user has authenticated to the device, which means that once the user enters the correct password or credentials to boot up the device or system, the data on the hard drive is decrypted and accessible to anyone who has physical access to the device or system, such as a thief or an attacker. This vulnerability can be exploited by using cold boot attacks, evil maid attacks, or other methods that target the device or system when it is powered on or in sleep mode. The other options are not examples of vulnerabilities of FDE, as FDE does not affect the ability to restore, backup, or transmit data.
References: Official (ISC)2 CISSP CBK Reference, Fifth Edition, Domain 3: Security Architecture and Engineering, pp. 483-484; CISSP All-in-One Exam Guide, Eighth Edition, Chapter 7: Security Architecture and Engineering, pp. 697-698.