220-802 · Question #870
A PC administrator is trying to implement BitLocker full disk encryption but the PC reports that a security module is not found. Which of the following should the administrator do to correct this?
The correct answer is D. Enable TPM in the BIOS. BitLocker requires a Trusted Platform Module (TPM) chip to store encryption keys. If the TPM is not enabled in the BIOS/UEFI firmware, BitLocker reports that no security module is found.
Question
A PC administrator is trying to implement BitLocker full disk encryption but the PC reports that a security module is not found. Which of the following should the administrator do to correct this?
Options
- AEnable the BIOS password
- BTurn UAC off
- CCreate a separate partition with EFS
- DEnable TPM in the BIOS
How the community answered
(26 responses)- A15% (4)
- B4% (1)
- C8% (2)
- D73% (19)
Why each option
BitLocker requires a Trusted Platform Module (TPM) chip to store encryption keys. If the TPM is not enabled in the BIOS/UEFI firmware, BitLocker reports that no security module is found.
A BIOS password authenticates access to firmware settings but is unrelated to the TPM hardware module that BitLocker requires for key storage.
User Account Control (UAC) manages privilege elevation in Windows and has no role in BitLocker's hardware security module detection.
EFS (Encrypting File System) provides file-level encryption and does not require or emulate a TPM; it also does not fulfill BitLocker's full-disk encryption TPM requirement.
BitLocker uses the TPM to securely store the volume master key and to verify system integrity at boot time. The TPM chip may be physically present on the motherboard but disabled in the UEFI/BIOS settings by default; enabling it in the firmware configuration allows BitLocker to detect and use the module, resolving the error.
Concept tested: BitLocker full disk encryption TPM requirement
Source: https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/
Topics
Community Discussion
No community discussion yet for this question.