Checklist

Encrypted volume review checklist

For learners working through Vault Audit Fundamentals Module 2

Padlock on a computer keyboard

Encryption slogans age poorly. A review that only asks “is it encrypted?” misses mounts that bypass the volume, keys stored beside the data, and exports that left the boundary last spring. Use this sequence when you have a quiet afternoon and a non-production target.

1. Name the object

Write the volume label, host, path, and owner in one line. If two people disagree on the name, stop and reconcile before testing controls. Misnamed surfaces create duplicate findings and false closes.

2. Confirm what encryption covers

Distinguish full-volume encryption, folder-level tools, and application-level sealing. Note any plaintext cache, search index, or thumbnail store that sits outside the cipher. Screenshot the setting that proves the mode — not a marketing page.

3. Trace key custody

Ask where unlock material lives, who can export it, and whether a laptop reboot still leaves a session unlocked. If the answer is “the vendor handles it,” record which console role can still rotate or escrow keys.

4. Check the quiet exits

Look for scheduled sync jobs, offline packs, and “temporary” share links. Encryption on the primary volume does not travel with every copy unless you verify it.

5. Write one re-runnable finding

Pick the strongest gap you found and write: evidence, interpretation, next check. Leave adjectives out. Tomorrow’s reviewer should be able to repeat your step without a call.

Want guided labs? See Vault Audit Fundamentals or the Secure Storage Review Center overview.

Educational content only. Not Financial Advice.