220-1201 · Question #54
A systems administrator deploys BitLocker to all devices. However, one of the desktop PCs is not able to encrypt the boot drive. Which of the following should the administrator check?
The correct answer is A. TPM. BitLocker Drive Encryption in Windows requires a Trusted Platform Module (TPM)to encrypt the boot drive securely. The TPM is a dedicated microcontroller designed to secure hardware through integrated cryptographic keys. It validates system integrity during boot and securely…
Question
A systems administrator deploys BitLocker to all devices. However, one of the desktop PCs is not able to encrypt the boot drive. Which of the following should the administrator check?
Options
- ATPM
- BCPU
- CRAM
- DHDD
How the community answered
(24 responses)- A71% (17)
- B8% (2)
- C17% (4)
- D4% (1)
Explanation
BitLocker Drive Encryption in Windows requires a Trusted Platform Module (TPM)to encrypt the boot drive securely. The TPM is a dedicated microcontroller designed to secure hardware through integrated cryptographic keys. It validates system integrity during boot and securely stores the encryption keys. If BitLocker cannot find a TPM or it is disabled in BIOS/UEFI, drive encryption cannot proceed. BitLocker can function without TPM using a USB startup key, but this compromises some security and is not recommended for managed enterprise environments.
Topics
Community Discussion
No community discussion yet for this question.