220-1101 exam dumps

220-1101 practice question 286 of 471

A+ Core 1. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1101 Question 286

Single answerTPM

A technician is preparing several office PCs for a Windows 11 deployment. One desktop has a TPM header on the motherboard, but the installer reports that no compatible TPM is available. The company wants to use BitLocker with hardware-based key protection and meet Windows 11 security requirements without replacing the motherboard. Which action should the technician take FIRST?

  1. A

    Install a discrete TPM module that matches the motherboard's supported TPM version and connector

  2. B

    Enable Secure Boot in UEFI and leave the TPM settings unchanged

  3. C

    Replace the HDD with an SSD so the system can meet Windows 11 security requirements

  4. D

    Disable BitLocker requirements in Local Group Policy so TPM hardware is no longer needed

Show answer and explanation

Correct answer: A

Explanation

This scenario tests practical understanding of TPM deployment rather than simple definition recall. A motherboard TPM header is only a connector; it does not guarantee that a TPM is installed. For Windows 11, Microsoft requires TPM 2.0, and BitLocker commonly uses TPM hardware to protect encryption keys and support secure boot measurements. Best practice is to first confirm whether the system has a firmware TPM option in UEFI/BIOS (such as Intel PTT or AMD fTPM). If none is present or available, the technician should install a compatible discrete TPM module supported by the motherboard manufacturer. Microsoft documentation for Windows 11 hardware requirements specifies TPM 2.0, and Microsoft BitLocker documentation explains TPM-based protector usage. Secure Boot complements TPM but does not replace it.

  • A. Correct.

    Correct. A TPM header does not mean a TPM chip is already present. If the system board supports it, installing the correct discrete TPM module is the appropriate first step when no firmware TPM is available or enabled. This supports Windows 11 requirements and allows BitLocker to use TPM-based key protection. The technician must verify motherboard compatibility, supported TPM version (typically TPM 2.0 for Windows 11), and vendor-specific connector requirements before installation.

  • B. Incorrect.

    Incorrect. Secure Boot and TPM are related but separate security features. Enabling Secure Boot alone will not create TPM functionality if the system does not currently have an active TPM. A system can have Secure Boot enabled and still fail the TPM requirement for Windows 11 or TPM-based BitLocker usage.

  • C. Incorrect.

    Incorrect. Replacing an HDD with an SSD may improve performance, but it does not address the lack of a TPM. Storage type is not what determines TPM availability, and changing drives will not satisfy Windows 11's TPM 2.0 requirement.

  • D. Incorrect.

    Incorrect. While BitLocker can be configured in some environments to operate without a TPM by using a startup key or password, that does not satisfy the company's stated goal of using hardware-based key protection. It also does not resolve Windows 11's TPM requirement. This option reflects a common misconception that policy changes can substitute for the hardware security feature itself.

Timed practice exam

Take a 220-1101 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam