CompTIA A+ Core 2 (220-1202)SecurityMedium

A network administrator is configuring BitLocker on a new Windows 11 workstation. The computer has a Trusted Platform Module (TPM) chip installed. To ensure the highest level of security and prevent unauthorized boot attempts, which BitLocker configuration should the administrator choose?

  1. ATPM only
  2. BTPM + PIN
  3. CTPM + USB Key
  4. DPassword only
Show answer & explanation

Correct answer: B. TPM + PIN

TPM + PIN offers the highest level of protection against unauthorized boot access for BitLocker. The PIN provides an additional layer of authentication that must be entered by the user before the system can access the TPM and decrypt the drive, protecting against cold boot attacks or physical theft where the TPM alone might be bypassed.

Why the other options are wrong

  • A. TPM only provides good security but is vulnerable to cold boot attacks or physical removal of the drive if an attacker has physical access.
  • C. TPM + USB Key requires something you have (TPM) and something you have (USB), which is strong but the USB key can be lost or stolen.
  • D. Password only does not leverage the hardware-based security features of the TPM, making it less secure than options involving the TPM.

BitLocker with TPM + PIN

A BitLocker configuration that uses both the Trusted Platform Module (TPM) for hardware-based encryption key storage and a user-entered Personal Identification Number (PIN) for pre-boot authentication, offering enhanced security.

  • Requires a TPM chip
  • Adds a 'something you know' factor (PIN) to the TPM's 'something you have' (hardware token)
  • Protects against cold boot attacks and physical drive removal

Memory trick: TPM plus a PIN gives you the strongest lock on your BitLocker.

More Security questions