🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your organization is rolling out company-owned Windows 11 laptops that must use full disk encryption. Security policy states: 1) a cryptographic key must be sealed in tamper-resistant hardware so the OS can verify boot integrity; 2) if a laptop is lost, it must not boot without user interaction; 3) the help-desk team needs the ability to recover data even if an employee forgets the unlock secret. Which implementation best satisfies all of these key-management requirements while minimizing user impact during normal startups?

  • Enable BitLocker in TPM + PIN mode and configure Group Policy to escrow recovery keys to Active Directory Domain Services for authorized help-desk retrieval.

  • Enable BitLocker in TPM-only mode and configure Group Policy to automatically back up recovery keys to Active Directory Domain Services.

  • Enable Encrypting File System (EFS) on user profiles and require users to store their private keys on hardware security (smart-card) tokens managed by IT.

  • Install third-party software-based volume encryption that uses a user-selected password stored in a local configuration file with no automated key escrow.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot