SY0-701 exam dumps

SY0-701 practice question 88 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 88

Single answerHardware

A security administrator is deploying new laptops to executives who frequently travel internationally. The company is concerned about attackers stealing a powered-off laptop and attempting to read sensitive data directly from the storage device or by booting from removable media. The administrator wants a hardware-based control that stores cryptographic keys securely and works with full-disk encryption to reduce this risk. Which of the following is the BEST solution?

  1. A

    Enable a TPM and use it with full-disk encryption

  2. B

    Install a USB token for multifactor authentication only

  3. C

    Configure a BIOS password without disk encryption

  4. D

    Use a screen lock with a short inactivity timer

Show answer and explanation

Correct answer: A

Explanation

The best answer is to enable a TPM and use it with full-disk encryption. In Security+ hardware scenarios, TPM is the key hardware component associated with protecting cryptographic keys and supporting secure boot and disk-encryption use cases. This is especially important for laptops that may be lost or stolen. Full-disk encryption protects data at rest, while TPM helps safeguard the encryption keys in hardware rather than leaving them exposed in software alone. By contrast, BIOS/UEFI passwords and screen locks are access controls, not strong protections against offline data theft. USB tokens can be useful for multifactor authentication, but they do not replace storage encryption. This aligns with common enterprise security guidance, including Microsoft BitLocker deployment recommendations and industry best practices for endpoint protection using hardware-backed key storage.

  • A. Correct.

    Correct. A Trusted Platform Module (TPM) is a hardware security component designed to securely store cryptographic material, including keys used by full-disk encryption solutions such as BitLocker. This helps protect data at rest if a laptop is stolen, especially against attempts to remove the drive or boot from external media. TPM-backed encryption is a standard best practice for protecting mobile endpoints.

  • B. Incorrect.

    Incorrect. A USB token can improve authentication for user logon or application access, but by itself it does not provide full-disk encryption or protect data stored on a stolen drive. Someone who removes the storage device could still attempt offline access if the disk itself is not encrypted.

  • C. Incorrect.

    Incorrect. A BIOS or UEFI password may restrict some boot actions, but it does not encrypt the contents of the drive. An attacker can often bypass this protection by removing the drive and reading it from another system. The misconception is treating boot restrictions as equivalent to data-at-rest protection.

  • D. Incorrect.

    Incorrect. A screen lock protects an active session from casual access when the device is left unattended, but it does not protect data on a powered-off stolen laptop. Once the device is off, a screen timeout setting provides no protection against offline attacks on the storage media.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam