SY0-701 exam dumps

SY0-701 practice question 357 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 357

Single answerAttestation

A company allows remote administrators to connect to a critical virtualization cluster only from approved laptops. After a recent security review, the company wants the VPN gateway to verify that each laptop booted with an unmodified firmware and boot chain before allowing access. The security engineer proposes using a hardware-based attestation process tied to the device's trusted platform module (TPM). Which of the following best describes what attestation provides in this scenario?

  1. A

    It proves to the VPN gateway that the laptop's measured boot state matches expected values stored or validated by a trusted authority.

  2. B

    It encrypts all administrator traffic end-to-end between the laptop and the virtualization hosts using the TPM's endorsement key.

  3. C

    It guarantees that malware cannot run on the laptop after the user has authenticated to the VPN.

  4. D

    It replaces the need for certificates by allowing the TPM to authenticate the user directly to the VPN.

Show answer and explanation

Correct answer: A

Explanation

Attestation is the process of proving characteristics of a system to another party, typically to establish trust in the platform's integrity. In Security+ terms, TPM-backed attestation is commonly associated with measured boot and remote verification of device health or trustworthiness. The TPM records measurements of firmware, bootloader, and other startup components into Platform Configuration Registers (PCRs). A verifier can then evaluate those measurements against expected baselines or trusted reference values before allowing sensitive access. This aligns with common guidance from the Trusted Computing Group (TCG) on TPM and attestation concepts and with enterprise best practices for conditional access based on device posture. The key distinction is that attestation provides evidence of system state; it does not itself provide full traffic encryption, eliminate the need for identity authentication, or guarantee that the device will remain uncompromised after the attestation check.

  • A. Correct.

    Correct. Attestation is used to provide evidence about a platform's integrity state, commonly by using TPM-backed measurements collected during boot. In a remote attestation workflow, those measurements can be compared against known-good values or evaluated by a verifier to determine whether the firmware and boot chain are in an expected state before granting access.

  • B. Incorrect.

    Incorrect. Attestation is about proving system state or integrity, not performing bulk end-to-end encryption for application traffic. While TPMs can protect keys and support cryptographic operations, the endorsement key is not used to transparently encrypt all administrator traffic to servers in this manner.

  • C. Incorrect.

    Incorrect. Attestation helps verify the device's state at a point in time, such as during measured boot or before access is granted. It does not guarantee that malware can never execute later. Post-boot compromise is still possible, so additional controls like EDR, application control, patching, and monitoring are needed.

  • D. Incorrect.

    Incorrect. Attestation does not replace user or device certificates in general, nor does it mean the TPM directly authenticates the user. TPM-based attestation can supplement device trust decisions, but user authentication still typically relies on credentials, certificates, MFA, or other identity mechanisms.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam