nerdexam
CompTIA

220-1102 · Question #447

A technician is setting up a new laptop. The company's security policy states that users cannot install virtual machines. Which of the following should the technician implement to prevent users from…

The correct answer is A. UEFI password. To prevent users from enabling virtual technology on their laptops, the technician should set a UEFI password, which restricts access to BIOS/UEFI settings where virtualization features are enabled or disabled.

Security

Question

A technician is setting up a new laptop. The company's security policy states that users cannot install virtual machines. Which of the following should the technician implement to prevent users from enabling virtual technology on their laptops?

Options

  • AUEFI password
  • BSecure boot
  • CAccount lockout
  • DDisable network drivers

How the community answered

(44 responses)
  • A
    73% (32)
  • B
    18% (8)
  • C
    7% (3)
  • D
    2% (1)

Why each option

To prevent users from enabling virtual technology on their laptops, the technician should set a UEFI password, which restricts access to BIOS/UEFI settings where virtualization features are enabled or disabled.

AUEFI passwordCorrect

A UEFI (Unified Extensible Firmware Interface) password, often referred to as a BIOS password, protects access to the system's firmware settings. Disabling virtualization technology features (like Intel VT-x or AMD-V) within the UEFI/BIOS and then setting an administrator password will prevent users from re-enabling them without the password.

BSecure boot

Secure Boot is a UEFI feature that ensures only signed, trusted operating system loaders can execute, but it does not directly control access to or prevent the enabling of virtualization technology.

CAccount lockout

Account lockout is an operating system security feature that prevents unauthorized access by locking an account after multiple failed login attempts; it does not control hardware virtualization settings.

DDisable network drivers

Disabling network drivers would prevent network connectivity but has no bearing on the ability to enable or disable virtualization technology in the system firmware.

Concept tested: UEFI/BIOS security for hardware features

Source: https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/uefi-firmware-settings

Topics

#UEFI/BIOS security#Firmware security#Endpoint security#Access control

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice