220-1101 exam dumps

220-1101 practice question 280 of 471

A+ Core 1. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1101 Question 280

Single answerSecure Boot

A technician replaces the failed hard drive in a Windows 11 laptop and restores the user's system image. After the restore, the laptop powers on but displays a firmware message stating that the boot image failed signature verification and the OS will not load. The user says the laptop was working normally before the drive failure. Which action should the technician take FIRST to restore normal startup while maintaining the system's security features?

  1. A

    Enter UEFI firmware settings and verify that Secure Boot is enabled with the factory default keys installed

  2. B

    Convert the drive from GPT to MBR so the firmware can detect the restored operating system

  3. C

    Disable TPM in firmware because TPM measurements can block the restored boot loader

  4. D

    Turn off Secure Boot permanently so the restored image can bypass signature checks

Show answer and explanation

Correct answer: A

Explanation

Secure Boot is part of the UEFI firmware security model and is intended to prevent unauthorized or tampered boot loaders from running during startup. In a real support scenario, after a disk replacement and image restore, a technician should first verify that the system is still configured correctly in UEFI and that Secure Boot keys are present and valid. On many systems, restoring default Secure Boot keys in firmware resolves signature verification issues caused by cleared or altered key databases. This approach aligns with Microsoft guidance for Windows 11, which requires UEFI and Secure Boot support, and with common OEM best practices for maintaining platform integrity. Converting the drive partition style or disabling TPM does not address the root cause of a Secure Boot validation error. Permanently disabling Secure Boot may be used only as a temporary diagnostic step in some environments, but it is not the best first action when maintaining security is a stated requirement.

  • A. Correct.

    Correct. Secure Boot is a UEFI feature that validates the digital signatures of boot loaders and related startup components. After a drive replacement or image restore, startup can fail if Secure Boot keys were cleared, changed, or not properly enrolled in firmware. The best first step is to check UEFI settings and confirm Secure Boot is enabled with the platform's default or properly enrolled keys. This preserves the intended security controls while addressing the signature verification failure.

  • B. Incorrect.

    Incorrect. Converting the disk from GPT to MBR is not the appropriate response to a Secure Boot signature error. Secure Boot is designed for UEFI systems, which commonly boot from GPT disks. Changing to MBR could break a Windows 11 installation and is unrelated to repairing signature validation issues.

  • C. Incorrect.

    Incorrect. TPM and Secure Boot are separate technologies, although they may work together in the overall trusted boot process. A TPM does not directly perform Secure Boot signature verification of the boot image in the way described here. Disabling TPM would reduce security and is not the correct first troubleshooting step for this error.

  • D. Incorrect.

    Incorrect. Disabling Secure Boot might allow some unsigned or improperly signed boot components to load, but it weakens system security and does not follow best practice when the goal is to restore normal startup while maintaining protections. Since the question asks for the first action that preserves security, permanently disabling Secure Boot is not appropriate.

Timed practice exam

Take a 220-1101 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam