SY0-501 · Question #554
Due to regulatory requirements, a security analyst must implement full drive encryption on a Windows file server. Which of the following should the analyst implement on the system to BEST meet this…
The correct answer is B. Ensure the hardware supports TPM, and enable it in the BIOS. D. Enable and configure BitLocker on the drives. To implement full drive encryption on a Windows server, BitLocker should be enabled on the drives, with its security significantly enhanced by leveraging a Trusted Platform Module (TPM) for key protection.
Question
Due to regulatory requirements, a security analyst must implement full drive encryption on a Windows file server. Which of the following should the analyst implement on the system to BEST meet this requirement? (Choose two.)
Options
- AEnable and configure EFS on the file system.
- BEnsure the hardware supports TPM, and enable it in the BIOS.
- CEnsure the hardware supports VT-X, and enable it in the BIOS.
- DEnable and configure BitLocker on the drives.
How the community answered
(60 responses)- A8% (5)
- B77% (46)
- C15% (9)
Why each option
To implement full drive encryption on a Windows server, BitLocker should be enabled on the drives, with its security significantly enhanced by leveraging a Trusted Platform Module (TPM) for key protection.
Encrypting File System (EFS) encrypts individual files and folders, not entire drives, thus failing to meet the full drive encryption requirement.
A Trusted Platform Module (TPM) is a hardware component that provides secure storage for cryptographic keys, which BitLocker leverages to protect the encryption keys and verify system integrity for robust full disk encryption.
VT-x (Virtualization Technology) is a hardware feature that enhances virtualization performance and is unrelated to providing or strengthening full drive encryption.
BitLocker is the built-in Windows feature specifically designed to provide full volume encryption for operating system drives, fixed data drives, and removable data drives, directly addressing the requirement for full drive encryption on a Windows file server.
Concept tested: Windows BitLocker full drive encryption with TPM
Source: https://learn.microsoft.com/en-us/windows/security/encryption/bitlocker/bitlocker-overview
Topics
Community Discussion
No community discussion yet for this question.