Microsoft
AZ-801 · Question #134
You plan to enable BitLocker Drive Encryption (BitLocker) on volume C of VM1. You need to ensure that the BitLocker recovery key for VM1 is stored in Active Directory. Which two Group Policy settings
Based on the provided 'Answer Area' image, the following two Group Policy settings should be configured: 1. Configure use of hardware-based encryption for operating system drives 2. Choose how BitLocker protected operating system drives can be recovered
Secure Windows Server on-premises and hybrid infrastructures
Question
You plan to enable BitLocker Drive Encryption (BitLocker) on volume C of VM1.
You need to ensure that the BitLocker recovery key for VM1 is stored in Active Directory.
Which two Group Policy settings should you configure first? To answer, select the settings in the answer area.
NOTE: Each correct selection is worth one point.
Answer Area
Setting
Allow network unlock at startup
Allow Secure Boot for integrity validation
Turn on BitLocker auto-unlock for fixed data drives
Require additional authentication at startup (Windows Server 2008 and Windows Vista)
Require use of pre-boot PIN with TPM (Windows Server 2008)
Allow devices compliant with InstantGo or HSTT to opt out of pre-boot PIN
Configure use of password for operating system drives
Configure use of hardware-based encryption for operating system drives
Choose how BitLocker protected operating system drives can be recovered
... (partial list of settings from image)
Explanation
Based on the provided 'Answer Area' image, the following two Group Policy settings should be configured:
- Configure use of hardware-based encryption for operating system drives
- Choose how BitLocker protected operating system drives can be recovered
Topics
#BitLocker#Group Policy#Active Directory#Encryption
Community Discussion
No community discussion yet for this question.