SY0-301 · Question #710
The administrator would like to implement hardware assisted full disk encryption on laptops. Which of the following would MOST likely be used to meet this goal?
The correct answer is A. TPM. A TPM (Trusted Platform Module) is a dedicated hardware security chip embedded on a motherboard that stores cryptographic keys, certificates, and measurements used for hardware-assisted encryption. It is the foundation of solutions like BitLocker (Windows) for full disk…
Question
The administrator would like to implement hardware assisted full disk encryption on laptops. Which of the following would MOST likely be used to meet this goal?
Options
- ATPM
- BUSB Drive
- CKey Escrow
- DPKI
How the community answered
(26 responses)- A92% (24)
- C4% (1)
- D4% (1)
Explanation
A TPM (Trusted Platform Module) is a dedicated hardware security chip embedded on a motherboard that stores cryptographic keys, certificates, and measurements used for hardware-assisted encryption. It is the foundation of solutions like BitLocker (Windows) for full disk encryption, binding the encryption keys to the hardware so the disk cannot be decrypted on a different machine. A USB drive can store keys but is removable and not 'hardware-assisted' in the TPM sense. Key escrow is a key management/recovery process. PKI is a framework for managing certificates, not a hardware encryption mechanism.
Topics
Community Discussion
No community discussion yet for this question.