A hospital provides tablets to its medical staff to enable them to more quickly access and edit patients' charts. The hospital wants to ensure that if a tablet is identified as lost or stolen and a remote command is issued, the risk of data loss can be mitigated within seconds. The tablets are configured as follows to meet hospital policy: β’ Full disk encryption is enabled. β’ "Always On" corporate VPN is enabled. β’ eFuse-backed keystore is enabled/ready. β’ Wi-Fi 6 is configured with SAE. β’ Location services is disabled. β’ Application allow list is unconfigured. Assuming the hospital policy cannot be changed, which of the following is the best way to meet the hospital's objective?
- ARevoke the user VPN and Wi-Fi certificates
- BCryptographically erase FDE volumes (correct answer)
- CIssue new MFA credentials to all users
- DConfigure the application allow list
Reveal answer & explanationHide answer
The correct answer is B. Option B: Cryptographically erase FDE volumes This option keeps traffic private / properly secured as required.



