6.1k views
5 votes
You work as the IT security administrator for a small corporate network. The employee in Office 1 is working on a very sensitive project. Management is concerned that if the hard drive in the computer were stolen, sensitive information could be compromised. As a result, you have been asked to encrypt the entire System volume. The Office1 computer has a built-in TPM on the motherboard. In this lab, your task is to configure BitLocker drive encryption as follows: From within the computer's BIOS, turn on and activate TPM Security. From Windows, turn on BitLocker for the System (C:) drive. Back up the recovery key to the CorpServer BU-Office1 folder. Encrypt the entire System (C:) drive. Use the new encryption mode. Run the BitLocker system check.

User Andyengle
by
7.8k points

1 Answer

6 votes

Final answer:

To secure sensitive data on a computer with BitLocker and TPM, one must activate TPM in the BIOS, enable BitLocker in Windows, backup the recovery key to a secure location, encrypt the entire system drive using the new encryption mode, and perform a system check to finalize the setup.

Step-by-step explanation:

Configuring BitLocker to encrypt a system volume with a TPM involves several steps to ensure the security of sensitive information on a computer. Below is a step-by-step guide to properly setting up BitLocker on the employee’s computer:

  1. Restart the computer and enter the BIOS setup. This process usually involves hitting a key like F2, F10, F12, DEL, or ESC during the boot process.
  2. Look for the security settings in the BIOS and locate the option to enable the TPM. Activate or enable TPM Security, then save the changes and exit the BIOS.
  3. Boot into Windows, open the Control Panel, and find the BitLocker Drive Encryption option. Click on “Turn on BitLocker” next to the System (C:) drive.
  4. The BitLocker setup wizard will prompt you to save the recovery key. Choose to back up the recovery key to the CorpServer BU-Office1 folder as instructed.
  5. Select the option to encrypt the entire drive, and make sure to choose the “new encryption mode” if available for enhanced security.
  6. Initiate the BitLocker encryption process. Be aware that this process can take a considerable amount of time depending on the size of the drive.
  7. Once the initial steps are complete, BitLocker will prompt you to run a system check to ensure everything is working correctly before the actual encryption of the disk begins. Be sure to continue with this system check to avoid any issues later on.

After these steps, the system volume will be encrypted, enhancing the security of sensitive data against physical theft of the hard drive.

User Ahad Porkar
by
7.9k points

No related questions found