nerdexam
CompTIA

SY0-301 · Question #710

The administrator would like to implement hardware assisted full disk encryption on laptops. Which of the following would MOST likely be used to meet this goal?

The correct answer is A. TPM. A TPM (Trusted Platform Module) is a dedicated hardware security chip embedded on a motherboard that stores cryptographic keys, certificates, and measurements used for hardware-assisted encryption. It is the foundation of solutions like BitLocker (Windows) for full disk…

Security architecture

Question

The administrator would like to implement hardware assisted full disk encryption on laptops. Which of the following would MOST likely be used to meet this goal?

Options

  • ATPM
  • BUSB Drive
  • CKey Escrow
  • DPKI

How the community answered

(26 responses)
  • A
    92% (24)
  • C
    4% (1)
  • D
    4% (1)

Explanation

A TPM (Trusted Platform Module) is a dedicated hardware security chip embedded on a motherboard that stores cryptographic keys, certificates, and measurements used for hardware-assisted encryption. It is the foundation of solutions like BitLocker (Windows) for full disk encryption, binding the encryption keys to the hardware so the disk cannot be decrypted on a different machine. A USB drive can store keys but is removable and not 'hardware-assisted' in the TPM sense. Key escrow is a key management/recovery process. PKI is a framework for managing certificates, not a hardware encryption mechanism.

Topics

#TPM#full disk encryption#hardware security#endpoint protection

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice