To protect the data that is stored on a device, we should implement Full Device Encryption (FDE). The device requires a Trusted Platform Module (TPM) chip to store the encryption keys.
For example, a salesperson has just received a new company laptop where the operating system had been hardened. The device used Bitlocker encryption, where the whole device is encrypted to protect the data stored on the hard drive. In the Security+ exam, this is known as FDE.
Containerization offers organizations the ability to deploy and manage corporate content securely in an encrypted space on the device. All corporate resources, such as proprietary applications, corporate emails, calendars, and contacts, reside within this managed space. We could also place an application inside a virtual machine to segregate it from the laptop.
Storage segmentation is where an external device is...