Microsoft
70-415 · Question #58
You need to recommend a solution for protecting the files stored on the laptop computers of the sales users. The solution must meet the sales department requirements. What should you recommend?
The correct answer is B. BitLocker Drive Encryption (BitLocker) that uses a password protector. All of the files on the laptop computers must be encrypted. Active Directory SID-based protector. This protector can be added to both operating system and data volumes, although it does not unlock operating system volumes in the pre-boot environment. The protector requires the SI
Design and prepare the desktop infrastructure
Question
You need to recommend a solution for protecting the files stored on the laptop computers of the sales users. The solution must meet the sales department requirements. What should you recommend?
Options
- ABitLocker Drive Encryption (BitLocker) that uses a SID-based protector
- BBitLocker Drive Encryption (BitLocker) that uses a password protector
- CEncrypting File System (EFS) that uses certificates from a certification authority (CA)
- DEncrypting File System (EFS) that uses self-signed certificates
How the community answered
(42 responses)- A5% (2)
- B81% (34)
- C2% (1)
- D12% (5)
Explanation
- All of the files on the laptop computers must be encrypted. Active Directory SID-based protector. This protector can be added to both operating system and data volumes, although it does not unlock operating system volumes in the pre-boot environment. The protector requires the SID for the domain account or group to link with the protector. BitLocker can protect a clusteraware disk by adding a SID-based protector for the Cluster Name Object (CNO) that lets the disk properly failover to and be unlocked by any member computer of The ADAccountOrGroup protector requires the use of an additional protector for use (such as TPM, PIN, or recovery key) when used on operating system volumes To add an ADAccountOrGroup protector to a volume requires either the actual domain SID or the group name preceded by the domain and a backslash. In the example below, the CONTOSO\Administrator account is added as a protector to the data volume G. Active Directory-based protectors are normally used to unlock Failover Cluster enabled volumes.
Topics
#BitLocker#drive encryption#password protector#laptop security
Community Discussion
No community discussion yet for this question.