220-801 · Question #720
Which of the following is required in order for BitLocker to be enabled?
The correct answer is C. Trusted platform module. BitLocker Drive Encryption requires a Trusted Platform Module (TPM) chip to securely store encryption keys and validate the boot environment's integrity before releasing them.
Question
Options
- ADrive encryption
- BGroup Policy
- CTrusted platform module
- DPower-on Password
How the community answered
(31 responses)- A3% (1)
- B6% (2)
- C87% (27)
- D3% (1)
Why each option
BitLocker Drive Encryption requires a Trusted Platform Module (TPM) chip to securely store encryption keys and validate the boot environment's integrity before releasing them.
Drive encryption is the function that BitLocker performs - it is the outcome of enabling BitLocker, not a prerequisite for it.
Group Policy can be used to manage and enforce BitLocker settings across an organization but is not required to enable BitLocker on a single device.
BitLocker uses the TPM chip to seal the volume master key against the measured state of the system's boot components. If the boot sequence is tampered with, the TPM detects the change and refuses to release the key, protecting the encrypted data. Without a TPM, BitLocker requires a USB startup key as an alternative, but a TPM is the standard hardware prerequisite.
A power-on password is a BIOS/UEFI feature that restricts booting and is independent of BitLocker's hardware requirements.
Concept tested: BitLocker TPM hardware prerequisite for drive encryption
Source: https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/bitlocker-overview
Topics
Community Discussion
No community discussion yet for this question.