nerdexam
CompTIA

SY0-501 · Question #554

Due to regulatory requirements, a security analyst must implement full drive encryption on a Windows file server. Which of the following should the analyst implement on the system to BEST meet this…

The correct answer is B. Ensure the hardware supports TPM, and enable it in the BIOS. D. Enable and configure BitLocker on the drives. To implement full drive encryption on a Windows server, BitLocker should be enabled on the drives, with its security significantly enhanced by leveraging a Trusted Platform Module (TPM) for key protection.

Submitted by kim_seoul· Mar 4, 2026Security architecture

Question

Due to regulatory requirements, a security analyst must implement full drive encryption on a Windows file server. Which of the following should the analyst implement on the system to BEST meet this requirement? (Choose two.)

Options

  • AEnable and configure EFS on the file system.
  • BEnsure the hardware supports TPM, and enable it in the BIOS.
  • CEnsure the hardware supports VT-X, and enable it in the BIOS.
  • DEnable and configure BitLocker on the drives.

How the community answered

(60 responses)
  • A
    8% (5)
  • B
    77% (46)
  • C
    15% (9)

Why each option

To implement full drive encryption on a Windows server, BitLocker should be enabled on the drives, with its security significantly enhanced by leveraging a Trusted Platform Module (TPM) for key protection.

AEnable and configure EFS on the file system.

Encrypting File System (EFS) encrypts individual files and folders, not entire drives, thus failing to meet the full drive encryption requirement.

BEnsure the hardware supports TPM, and enable it in the BIOS.Correct

A Trusted Platform Module (TPM) is a hardware component that provides secure storage for cryptographic keys, which BitLocker leverages to protect the encryption keys and verify system integrity for robust full disk encryption.

CEnsure the hardware supports VT-X, and enable it in the BIOS.

VT-x (Virtualization Technology) is a hardware feature that enhances virtualization performance and is unrelated to providing or strengthening full drive encryption.

DEnable and configure BitLocker on the drives.Correct

BitLocker is the built-in Windows feature specifically designed to provide full volume encryption for operating system drives, fixed data drives, and removable data drives, directly addressing the requirement for full drive encryption on a Windows file server.

Concept tested: Windows BitLocker full drive encryption with TPM

Source: https://learn.microsoft.com/en-us/windows/security/encryption/bitlocker/bitlocker-overview

Topics

#BitLocker#TPM#full disk encryption#regulatory compliance

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice