I want to create a persistent live USB of Debian and I wanted to use Veracrypt to protect the drive. From my understanding, when you boot up the drive, it doesn’t ask for a password. so if someone were to get a hold of the drive, they can just get immediate access. Also, I know it’s also recommend to encrypt your drives to protect your data. I want to know if it’s possible to do that.
If not, are there other ways to protect the drive?


You’d have a better experience with using LUKS encryption on your live bootable environment.