nerdexam
Microsoft

AZ-801 · Question #118

Which of the following security policies would you configure from the Security Settings extension of the Local Group Policy Editor to control Encrypting File System, Data Protection, and BitLocker…

The correct answer is D. Public Key Policies. Public Key Policies in Group Policy are used to manage certificate-based security features like Encrypting File System (EFS) and BitLocker recovery agents.

Secure Windows Server on-premises and hybrid infrastructures

Question

Which of the following security policies would you configure from the Security Settings extension of the Local Group Policy Editor to control Encrypting File System, Data Protection, and BitLocker Drive Encryption?

Options

  • AAccount Policies
  • BLocal Policies
  • CNetwork List Manager Policies
  • DPublic Key Policies
  • EApplication Control Policies

How the community answered

(39 responses)
  • A
    3% (1)
  • D
    95% (37)
  • E
    3% (1)

Why each option

Public Key Policies in Group Policy are used to manage certificate-based security features like Encrypting File System (EFS) and BitLocker recovery agents.

AAccount Policies
BLocal Policies
CNetwork List Manager Policies
DPublic Key PoliciesCorrect

Public Key Policies allow configuration of EFS recovery agents and certificate-based data recovery agents for BitLocker Drive Encryption, directly controlling these encryption features.

EApplication Control Policies

Application Control Policies like AppLocker control which applications can run, not file or disk encryption.

Concept tested: Group Policy-Public Key Policies for encryption

Source: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/enabling-an-e-f-s-recovery-agent

Topics

#Group Policy#BitLocker Drive Encryption#Encrypting File System (EFS)#Public Key Policies

Community Discussion

No community discussion yet for this question.

Full AZ-801 Practice