Answer:
a. Use BitLocker Encryption with the TPM chip.
b. Enable Secure boot.
Step-by-step explanation:
Bit Locker encryption is a feature included in Microsoft windows that to in pro and enterprise version only.it is full volume encryption.First it was introduced in windows Vista.It is crafted to protect the data by providing encryption.
Secure boot makes sure that the device boots using Operating system or software trusted by the manufacturer.