nerdexam
CompTIA

220-1002 · Question #602

A company recently upgraded its computers from Windows XP SP3 lo Windows 7. Due to budget constraints, the company was not able to purchase newer machines. The computers do not have TPM chips. Out…

The correct answer is B. BitLocker. BitLocker provides full-disk encryption in Windows 7 with centralized recovery key management and can operate without a TPM chip using a USB startup key, satisfying all stated requirements.

Hardware and network troubleshooting

Question

A company recently upgraded its computers from Windows XP SP3 lo Windows 7. Due to budget constraints, the company was not able to purchase newer machines. The computers do not have TPM chips. Out the company would like to secure the information on the local hard disk in case the hard drive is stolen, while being able to access all of its information even if users leave. Which of the following would allow the company to accomplish this task?

Options

  • AEncrypted file system
  • BBitLocker
  • CSecure Boot
  • DBIOS password

How the community answered

(25 responses)
  • A
    12% (3)
  • B
    76% (19)
  • C
    4% (1)
  • D
    8% (2)

Why each option

BitLocker provides full-disk encryption in Windows 7 with centralized recovery key management and can operate without a TPM chip using a USB startup key, satisfying all stated requirements.

AEncrypted file system

Encrypting File System encrypts individual files and folders tied to the encrypting user's certificate, so data may become inaccessible if a user leaves and key recovery is not pre-configured.

BBitLockerCorrect

BitLocker supports full-volume encryption in Windows 7 and can be configured to operate without a TPM by requiring a USB startup key at boot, directly addressing the no-TPM hardware constraint. Administrators can store BitLocker recovery keys centrally in Active Directory, ensuring the company retains access to all encrypted data regardless of employee turnover.

CSecure Boot

Secure Boot is a UEFI firmware feature that validates the boot environment's integrity but does not encrypt any data stored on the hard drive.

DBIOS password

A BIOS password restricts access to firmware settings but leaves hard drive data unencrypted and fully readable if the drive is removed and connected to another machine.

Concept tested: BitLocker full-disk encryption without TPM in Windows 7

Source: https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/bitlocker-overview

Topics

#BitLocker#full disk encryption#TPM#data security

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice