nerdexam
CompTIA

CV0-003 · Question #234

A company's security policy requires full disk encryption on all clients with preboot enabled. The encryption server is hosted, and the requirement is to push an update to all endpoints. Which of…

The correct answer is B. Access the web UI portal of the encryption server, apply the update to the test group, validate. Using the encryption server's web UI to apply an update to a pilot group first, validating preboot and encryption integrity, then performing a broad rollout minimizes disruption while preserving security controls.

Operations and Support

Question

A company's security policy requires full disk encryption on all clients with preboot enabled. The encryption server is hosted, and the requirement is to push an update to all endpoints. Which of the following is the BEST method to test and apply the update with minimal disruption to end users?

Options

  • AAccess the API of the encryption server, develop a custom script, and then update all endpoints.
  • BAccess the web UI portal of the encryption server, apply the update to the test group, validate,
  • CAdd the update to the standard desktop configuration image, apply the update to a test VM, and
  • DAccess the web UI of the encryption server and disable preboot, apply the update, test, and then

How the community answered

(17 responses)
  • A
    12% (2)
  • B
    76% (13)
  • C
    6% (1)
  • D
    6% (1)

Why each option

Using the encryption server's web UI to apply an update to a pilot group first, validating preboot and encryption integrity, then performing a broad rollout minimizes disruption while preserving security controls.

AAccess the API of the encryption server, develop a custom script, and then update all endpoints.

Developing a custom script against the encryption server API introduces additional engineering complexity and error risk that is unnecessary when a vendor-managed UI is available.

BAccess the web UI portal of the encryption server, apply the update to the test group, validate,Correct

The vendor-provided web UI portal is the supported, least-risk interface for managing the encryption server, reducing the chance of misconfiguration during an update. Applying the update to a test group first validates that preboot authentication and encryption remain functional before broader deployment. This staged approach ensures end-user disruption is contained to a small group while the change is validated.

CAdd the update to the standard desktop configuration image, apply the update to a test VM, and

Applying the update via a desktop configuration image to a test VM does not replicate the preboot authentication environment of physical endpoints, making the validation incomplete.

DAccess the web UI of the encryption server and disable preboot, apply the update, test, and then

Disabling preboot authentication before applying the update removes a critical security control and violates the company's security policy requiring preboot to be enabled at all times.

Concept tested: Staged update deployment for full disk encryption with preboot

Source: https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/bitlocker-management-for-enterprises

Topics

#patch management#change management#encryption update#test group rollout

Community Discussion

No community discussion yet for this question.

Full CV0-003 Practice