Encryption & Bitlocker

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/43

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:47 PM on 9/13/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

44 Terms

1
New cards

What protects data hosted on a file system when the OS mediates access to the device?

the operating system's security model

2
New cards

What describes the permissions that principals have on a file or folder?

an access control list (ACL)

3
New cards

When are file or folder permissions enforced?

when the OS mediates access to the device

4
New cards

Why could file permissions be overridden?

the disk is exposed to a different OS

5
New cards

What is data on persistent storage such as HDDs, SSDs, and thumb drives called?

data-at-rest

6
New cards

How can data-at-rest be protected against these risks?

encrypt the information stored on a disk

7
New cards

What does data-at-rest contrast with?

data-in-transit and data-in-use

8
New cards

What Windows feature of NTFS supports file and folder encryption?

Encrypting File System (EFS)

9
New cards

What edition of Windows does not include EFS?

Home edition

10
New cards

How do you apply EFS encryption to a file or folder?

open the file's or folder's property sheet, select Advanced, check Encrypt contents, then confirm the dialogs

11
New cards

How can encrypted folders and files be shown in Explorer?

with green color coding

12
New cards

What error will other users receive when trying to browse, copy, or print an encrypted file?

Access Denied

13
New cards

Without strong authentication, encrypted data is only as secure as what?

the user account password

14
New cards

What grants access to the key that performs file encryption and decryption?

the user's password

15
New cards

What can cause data loss with EFS?

the key being lost or damaged

16
New cards

What are examples of situations that can cause the key to be lost or damaged?

the user's profile is damaged, the user's password is reset by an administrator, or Windows is reinstalled

17
New cards

How can recovery be set up for EFS-encrypted data on a Windows domain?

back up the key to set up recovery agents with the ability to decrypt data

18
New cards
What is an alternative to file encryption?
full disk encryption (FDE)
19
New cards
What Windows disk encryption product provides full disk encryption?
BitLocker
20
New cards
Which Windows edition does not include BitLocker?
Home edition
21
New cards
What is the main advantage of full disk encryption?
it does not depend on the user to remember to encrypt data
22
New cards
What additional data does disk encryption also encrypt?
the swap file, print queues, temporary files, and so on
23
New cards
What types of drives can BitLocker be used with?
any volumes on fixed (internal) drives
24
New cards
What BitLocker form is used with removable drives?
BitLocker To Go
25
New cards
What must the user have access to in order to access encrypted data?
the encryption key
26
New cards
What chip can BitLocker use to tie the use of a fixed disk to a particular motherboard?
a trusted platform module (TPM) chip
27
New cards
What is the TPM used for with BitLocker?
storing the encryption key securely and ensuring the integrity of the OS used to boot the machine
28
New cards
What are alternatives to storing the BitLocker key in the TPM?
a removable smart card or a USB stick
29
New cards
What must the computer's firmware support for a USB startup key to work?
booting from USB
30
New cards
What must the TPM be configured with?
an owner password
31
New cards
How can TPM settings be managed from Windows?
the TPM Management snap-in
32
New cards
What is generated during BitLocker setup for drive recovery?
a recovery key
33
New cards
How should the BitLocker recovery key be stored?
on removable media or written down, stored securely and separately from the computer
34
New cards
What can the BitLocker recovery key be used for?
recovering the encrypted drive if the startup key is lost
35
New cards
What PowerShell cmdlet is used to turn on BitLocker for a volume?
Enable-BitLocker
36
New cards
What does -MountPoint "DriveLetter:" specify?
the drive you want to encrypt
37
New cards
What does -EncryptionMethod MethodName define?
the encryption algorithm and strength to use
38
New cards
What does -UsedSpaceOnly:$true do?
encrypt only the space currently in use
39
New cards
What does -UsedSpaceOnly:$false do?
encrypt the entire drive, including free space
40
New cards
What does -RecoveryKeyPath "Path" specify?
a folder path where the recovery key file should be stored
41
New cards
What does -RecoveryKeyProtector add?
a recovery key protector so the drive can be unlocked using a recovery key file if needed
42
New cards
What does -TpmProtector use as a protector?
the Trusted Platform Module (TPM) on the system
43
New cards
What does -SkipHardwareTest:$true do?
skips the hardware test and starts encryption immediately
44
New cards
What does -SkipHardwareTest:$false do?
requires a restart to validate the BitLocker configuration before encryption begins