220-1002 · Question #555
A technician is encrypting the company's laptops using BitLocker, but some of the laptops do not have a built-in TPM. Which of the following would enable the technician to use BitLocker on these…
The correct answer is A. A USB key. BitLocker normally relies on a Trusted Platform Module (TPM) chip to store encryption keys securely. When no TPM is present, BitLocker can be configured (via Group Policy) to use a USB flash drive as a startup key. The USB drive stores the encryption key, and the user must plug…
Question
A technician is encrypting the company's laptops using BitLocker, but some of the laptops do not have a built-in TPM. Which of the following would enable the technician to use BitLocker on these machines?
Options
- AA USB key
- BA firmware update
- CA local disk
- DTwo-factor authentication
How the community answered
(29 responses)- A86% (25)
- B7% (2)
- C3% (1)
- D3% (1)
Explanation
BitLocker normally relies on a Trusted Platform Module (TPM) chip to store encryption keys securely. When no TPM is present, BitLocker can be configured (via Group Policy) to use a USB flash drive as a startup key. The USB drive stores the encryption key, and the user must plug it in each time the computer boots to decrypt the drive. A firmware update (B) cannot create a TPM where none exists. A local disk (C) is already what BitLocker is encrypting - it cannot serve as its own key store. Two-factor authentication (D) is an access control method and does not substitute for TPM functionality in BitLocker's encryption key storage.
Topics
Community Discussion
No community discussion yet for this question.