CompTIA Server+ SK0-005 Practice Question
An organization installs rack-mount servers in a co-location datacenter. Security policy states that if a chassis is physically removed, an attacker must be unable to start the machine from external media or modify any firmware settings. The servers must still complete unattended reboots after scheduled patching without human intervention. Which type of UEFI firmware password should the administrator configure to meet these requirements?
Enable an ATA drive-lock password for each installed hard drive or SSD.
Store a Trusted Platform Module (TPM) owner password during Windows provisioning.
Configure a power-on (system/user) password that is prompted on every boot.
Configure an administrator (setup) password in the UEFI firmware.