nerdexam
CompTIA

220-802 · Question #870

A PC administrator is trying to implement BitLocker full disk encryption but the PC reports that a security module is not found. Which of the following should the administrator do to correct this?

The correct answer is D. Enable TPM in the BIOS. BitLocker requires a Trusted Platform Module (TPM) chip to store encryption keys. If the TPM is not enabled in the BIOS/UEFI firmware, BitLocker reports that no security module is found.

Hardware

Question

A PC administrator is trying to implement BitLocker full disk encryption but the PC reports that a security module is not found. Which of the following should the administrator do to correct this?

Options

  • AEnable the BIOS password
  • BTurn UAC off
  • CCreate a separate partition with EFS
  • DEnable TPM in the BIOS

How the community answered

(26 responses)
  • A
    15% (4)
  • B
    4% (1)
  • C
    8% (2)
  • D
    73% (19)

Why each option

BitLocker requires a Trusted Platform Module (TPM) chip to store encryption keys. If the TPM is not enabled in the BIOS/UEFI firmware, BitLocker reports that no security module is found.

AEnable the BIOS password

A BIOS password authenticates access to firmware settings but is unrelated to the TPM hardware module that BitLocker requires for key storage.

BTurn UAC off

User Account Control (UAC) manages privilege elevation in Windows and has no role in BitLocker's hardware security module detection.

CCreate a separate partition with EFS

EFS (Encrypting File System) provides file-level encryption and does not require or emulate a TPM; it also does not fulfill BitLocker's full-disk encryption TPM requirement.

DEnable TPM in the BIOSCorrect

BitLocker uses the TPM to securely store the volume master key and to verify system integrity at boot time. The TPM chip may be physically present on the motherboard but disabled in the UEFI/BIOS settings by default; enabling it in the firmware configuration allows BitLocker to detect and use the module, resolving the error.

Concept tested: BitLocker full disk encryption TPM requirement

Source: https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/

Topics

#BitLocker#TPM#full disk encryption#BIOS settings

Community Discussion

No community discussion yet for this question.

Full 220-802 Practice