nerdexam
CompTIA

220-1002 · Question #555

A technician is encrypting the company's laptops using BitLocker, but some of the laptops do not have a built-in TPM. Which of the following would enable the technician to use BitLocker on these…

The correct answer is A. A USB key. BitLocker normally relies on a Trusted Platform Module (TPM) chip to store encryption keys securely. When no TPM is present, BitLocker can be configured (via Group Policy) to use a USB flash drive as a startup key. The USB drive stores the encryption key, and the user must plug…

Hardware

Question

A technician is encrypting the company's laptops using BitLocker, but some of the laptops do not have a built-in TPM. Which of the following would enable the technician to use BitLocker on these machines?

Options

  • AA USB key
  • BA firmware update
  • CA local disk
  • DTwo-factor authentication

How the community answered

(29 responses)
  • A
    86% (25)
  • B
    7% (2)
  • C
    3% (1)
  • D
    3% (1)

Explanation

BitLocker normally relies on a Trusted Platform Module (TPM) chip to store encryption keys securely. When no TPM is present, BitLocker can be configured (via Group Policy) to use a USB flash drive as a startup key. The USB drive stores the encryption key, and the user must plug it in each time the computer boots to decrypt the drive. A firmware update (B) cannot create a TPM where none exists. A local disk (C) is already what BitLocker is encrypting - it cannot serve as its own key store. Two-factor authentication (D) is an access control method and does not substitute for TPM functionality in BitLocker's encryption key storage.

Topics

#BitLocker#TPM#USB startup key#drive encryption

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice