nerdexam
CompTIA

220-1201 · Question #54

A systems administrator deploys BitLocker to all devices. However, one of the desktop PCs is not able to encrypt the boot drive. Which of the following should the administrator check?

The correct answer is A. TPM. BitLocker Drive Encryption in Windows requires a Trusted Platform Module (TPM)to encrypt the boot drive securely. The TPM is a dedicated microcontroller designed to secure hardware through integrated cryptographic keys. It validates system integrity during boot and securely…

Submitted by marco_it· Mar 30, 2026Cloud Computing Design Considerations

Question

A systems administrator deploys BitLocker to all devices. However, one of the desktop PCs is not able to encrypt the boot drive. Which of the following should the administrator check?

Options

  • ATPM
  • BCPU
  • CRAM
  • DHDD

How the community answered

(24 responses)
  • A
    71% (17)
  • B
    8% (2)
  • C
    17% (4)
  • D
    4% (1)

Explanation

BitLocker Drive Encryption in Windows requires a Trusted Platform Module (TPM)to encrypt the boot drive securely. The TPM is a dedicated microcontroller designed to secure hardware through integrated cryptographic keys. It validates system integrity during boot and securely stores the encryption keys. If BitLocker cannot find a TPM or it is disabled in BIOS/UEFI, drive encryption cannot proceed. BitLocker can function without TPM using a USB startup key, but this compromises some security and is not recommended for managed enterprise environments.

Topics

#BitLocker#TPM#full disk encryption#security

Community Discussion

No community discussion yet for this question.

Full 220-1201 Practice