220-1101 · Question #958
While reviewing options in the BIOS/UEFI settings page to fix a laptop issue, a support technician notices an option to clear existing TPM keys. Which of the following would most likely happen if the
The correct answer is A. Encrypted hard drives would probably not be accessible.. The TPM (Trusted Platform Module) chip securely stores the cryptographic keys used by disk encryption solutions such as BitLocker. When BitLocker encrypts a drive, it seals the encryption key to the TPM, meaning the drive can only be unlocked by that specific TPM. If the TPM is c
Question
While reviewing options in the BIOS/UEFI settings page to fix a laptop issue, a support technician notices an option to clear existing TPM keys. Which of the following would most likely happen if the TPM is cleared?
Options
- AEncrypted hard drives would probably not be accessible.
- BAll security certificates would need to be reinstalled from trusted roots.
- CThe device would need to be reenrolled in the MDM platform
- DThe laptop would need to be registered to the domain as a new client.
How the community answered
(22 responses)- A77% (17)
- B5% (1)
- C5% (1)
- D14% (3)
Explanation
The TPM (Trusted Platform Module) chip securely stores the cryptographic keys used by disk encryption solutions such as BitLocker. When BitLocker encrypts a drive, it seals the encryption key to the TPM, meaning the drive can only be unlocked by that specific TPM. If the TPM is cleared, those stored keys are permanently deleted. As a result, any drives encrypted using TPM-bound keys become inaccessible - the data is still encrypted but the key to unlock it is gone. The other options (reinstalling certificates, MDM re-enrollment, domain re-registration) may be secondary consequences in some environments, but loss of drive access is the immediate and most critical impact.
Topics
Community Discussion
No community discussion yet for this question.