nerdexam
CompTIA

220-1101 · Question #165

A university student was able to boot from a live Linux CD on a computer in a shared space on campus. Which of the following will BEST prevent this type of action from occurring in the future?

The correct answer is D. Enable secure boot.. Secure Boot is a UEFI firmware feature that cryptographically validates the digital signature of any bootloader before allowing it to run. Live Linux distributions (unless specifically signed and trusted by the UEFI database) will fail this signature check and be blocked. This is

Hardware

Question

A university student was able to boot from a live Linux CD on a computer in a shared space on campus. Which of the following will BEST prevent this type of action from occurring in the future?

Options

  • ARequire TPM security features.
  • BSet a boot password.
  • CDisable all media options.
  • DEnable secure boot.

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    6% (3)
  • C
    4% (2)
  • D
    88% (46)

Explanation

Secure Boot is a UEFI firmware feature that cryptographically validates the digital signature of any bootloader before allowing it to run. Live Linux distributions (unless specifically signed and trusted by the UEFI database) will fail this signature check and be blocked. This is the most robust solution because it prevents unauthorized OS images from executing at the firmware level. Setting a boot password (B) prevents changes to BIOS/UEFI settings but may not block pre-configured boot order entries. Disabling media options (C) would work but is overly disruptive and can still be circumvented if BIOS access is possible. TPM (A) assists with encryption and platform integrity attestation but does not by itself block booting from external media.

Topics

#Secure Boot#UEFI security#Boot control#System security

Community Discussion

No community discussion yet for this question.

Full 220-1101 Practice