nerdexam
CompTIA

220-1201 · Question #366

An organization upgrades all desktops to Windows 11 and must ensure protection from malicious software at startup. Which option should be enabled?

The correct answer is C. Secure Boot. Secure Boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM). When the PC starts, Secure Boot checks the signature of each piece of boot software…

Submitted by takeshi77· Mar 30, 2026Security

Question

An organization upgrades all desktops to Windows 11 and must ensure protection from malicious software at startup. Which option should be enabled?

Options

  • ATrusted Platform Module
  • BHardware security module
  • CSecure Boot
  • DBIOS password

How the community answered

(32 responses)
  • B
    3% (1)
  • C
    94% (30)
  • D
    3% (1)

Explanation

Secure Boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM). When the PC starts, Secure Boot checks the signature of each piece of boot software (drivers, EFI applications, and the operating system). If the signatures are valid, the PC boots, and the OS takes control of the hardware. This prevents malware (such as rootkits) from loading during the startup process. Windows 11 requires Secure Boot to be enabled by default as part of its system requirements to provide enhanced security.

Topics

#Secure Boot#Boot security#Windows 11 security

Community Discussion

No community discussion yet for this question.

Full 220-1201 Practice