SY0-701 exam dumps

SY0-701 practice question 89 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 89

Single answerFirmware

A security administrator is responding to a report that several laptops in a finance department are loading an unauthorized bootloader before the operating system starts. The systems use UEFI firmware and support TPM. Management wants a control that will help prevent unsigned or tampered boot components from loading during startup on newly deployed laptops. Which of the following should the administrator implement FIRST?

  1. A

    Enable Secure Boot in UEFI firmware

  2. B

    Disable the TPM in firmware settings

  3. C

    Install a host-based firewall on each laptop

  4. D

    Configure full-disk encryption inside the operating system

Show answer and explanation

Correct answer: A

Explanation

The best answer is to enable Secure Boot. The scenario describes tampering in the pre-boot process, which is exactly the area Secure Boot is intended to protect in UEFI-based systems. Secure Boot checks that bootloaders, option ROMs, and related boot components are signed by trusted authorities before execution. This helps defend against bootkits and other early-boot malware. TPM support is also valuable, especially for measured boot and protecting cryptographic keys, but TPM is complementary rather than the first control to stop unsigned boot components from loading. Host-based firewalls and operating-system-level encryption are important endpoint protections, but they do not directly control what runs before the OS starts. This aligns with common vendor and standards guidance for platform integrity, including UEFI Secure Boot best practices and TPM-based trusted startup recommendations from major platform security documentation.

  • A. Correct.

    Correct. Secure Boot is a UEFI firmware feature that validates bootloaders and other early startup components against trusted signatures before they are allowed to run. This is specifically designed to help prevent unauthorized or tampered pre-boot code from loading. In this scenario, the issue occurs before the operating system starts, so a firmware-based boot integrity control is the most appropriate first step.

  • B. Incorrect.

    Incorrect. Disabling the TPM would reduce platform security, not improve it. TPMs are commonly used to support measured boot, key protection, and attestation. While TPM alone does not replace Secure Boot, turning it off would remove useful hardware-backed trust capabilities rather than stopping unauthorized bootloaders.

  • C. Incorrect.

    Incorrect. A host-based firewall operates after the operating system has booted and network services are running. It does not validate firmware, bootloaders, or pre-OS startup components. Someone might choose this if they are thinking generally about endpoint security, but it does not address the specific firmware-stage threat described.

  • D. Incorrect.

    Incorrect. Full-disk encryption protects data at rest and can use TPM integration, but it does not by itself prevent an unsigned or malicious bootloader from attempting to execute. Depending on the configuration, encryption can help detect some boot changes, but the primary control for allowing only trusted signed boot components in UEFI environments is Secure Boot.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam