ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 233 - SY0-601 discussion

Report
Export

A retail store has a business requirement to deploy a kiosk computer In an open area The kiosk computer's operating system has been hardened and tested. A security engineer IS concerned that someone could use removable media to install a rootkit Mich of the should the security engineer configure to BEST protect the kiosk computer?

A.
Measured boot
Answers
A.
Measured boot
B.
Boot attestation
Answers
B.
Boot attestation
C.
UEFI
Answers
C.
UEFI
D.
EDR
Answers
D.
EDR
Suggested answer: B

Explanation:

Boot attestation is a security feature that enables the computer to verify the integrity of its operating system before it boots. It does this by performing a hash of the operating system and comparing it to the expected hash of the operating system. If the hashes do not match, the computer will not boot and the rootkit will not be allowed to run. This process is also known as measured boot or secure boot.

According to the CompTIA Security+ Study Guide, “Secure Boot is a feature of Unified Extensible Firmware Interface (UEFI) that ensures that code that is executed during the boot process has been authenticated by a cryptographic signature. Secure Boot prevents malicious code from running at boot time, thus providing assurance that the system is executing only code that is legitimate. This provides a measure of protection against rootkits and other malicious code that is designed to run at boot time.”

asked 02/10/2024
Daniel Adebayo
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first