easyMultiple ChoiceObjective-mapped
220-1201 Practice Question: A technician is configuring a new workstation for…
A technician is configuring a new workstation for a secure environment. The policy requires that only signed operating systems can boot. Which UEFI feature should be enabled?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Secure Boot
Secure Boot ensures that only software signed with trusted certificates can boot. This prevents unauthorized bootloaders and rootkits. This tests knowledge of UEFI security features.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Legacy Boot (CSM)
Why it's wrong here
Enabling Legacy Boot, also known as Compatibility Support Module (CSM), allows the UEFI firmware to emulate a traditional BIOS environment. This permits booting from older operating systems and bootloaders that do not support UEFI or Secure Boot, often lacking digital signature verification. Consequently, CSM would permit the execution of unsigned boot code, directly contravening any security policy requiring bootloader signature validation.
- ✓
Enable Secure Boot
Why this is correct
Enabling Secure Boot is the correct action to ensure the integrity of the boot process by verifying the digital signature of every component in the boot chain, from the firmware to the operating system loader. It prevents unauthorized or malicious code from executing during startup by only allowing digitally signed and trusted bootloaders to launch. This mechanism directly addresses the requirement for bootloader signature verification, enhancing system security against rootkits and boot-level malware.
- ✗
Enable TPM
Why it's wrong here
Enabling the Trusted Platform Module (TPM) provides hardware-based security features such as cryptographic key generation, storage, and platform integrity measurements. While TPM can be used in conjunction with Secure Boot for advanced features like BitLocker drive encryption and remote attestation, its primary function is not to directly verify the digital signatures of bootloaders. TPM ensures the integrity of the system state after the bootloader has loaded, rather than enforcing the signature validation during the boot process itself.
- ✗
Set boot order to network first
Why it's wrong here
Setting the boot order to network first merely dictates the sequence in which the system attempts to load an operating system from various storage devices or network sources. While it can be useful for network installations or diskless workstations, modifying the boot order does not implement or enforce any security policies regarding the digital signatures of bootloaders. The system would still attempt to boot whatever it finds first in the specified order, regardless of its signature status, unless Secure Boot is also enabled.
Go deeper
Related to this question
About these practice questions
This 220-1201 question is part of Courseiva's 972-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1201 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1201 exam.