nerdexam
Microsoft

98-368 · Question #26

This question requires that you evaluate the underlined text to determine if it is correct. When BitLocker is enabled and and protecting a local drive, Trusted Platform Module (TPM) provides "pre…

The correct answer is C. a location that stores recovery keys for removable drives. Computers that incorporate a TPM have the ability to create cryptographic keys and encrypt them so that they can be decrypted only by the TPM. This process, often called "wrapping" or "binding" a key, can help protect the key from disclosure. Each TPM has a root "wrapping" key…

Understanding Device Security

Question

This question requires that you evaluate the underlined text to determine if it is correct. When BitLocker is enabled and and protecting a local drive, Trusted Platform Module (TPM) provides "pre- start system integrity verification for system and operating system drives". Instructions: Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice than makes the statement correct.

Options

  • ANo change is needed
  • B256-bit encryption that uses Advanced Encryption Standard (AES)
  • Ca location that stores recovery keys for removable drives
  • Dboot sector mapping for the startup process

How the community answered

(37 responses)
  • A
    16% (6)
  • B
    3% (1)
  • C
    76% (28)
  • D
    5% (2)

Explanation

Computers that incorporate a TPM have the ability to create cryptographic keys and encrypt them so that they can be decrypted only by the TPM. This process, often called "wrapping" or "binding" a key, can help protect the key from disclosure. Each TPM has a root "wrapping" key, called the Storage Root Key (SRK), which is stored within the TPM itself. The private portion of a key created in a TPM is never exposed to any other component, software, process, or person. https://technet.microsoft.com/en-us/library/cc749022%28v=ws.10%29.aspx

Topics

#BitLocker#TPM#pre-boot authentication#drive encryption

Community Discussion

No community discussion yet for this question.

Full 98-368 Practice