hardMultiple ChoiceObjective-mapped
220-1201 Practice Question: Migrating its fleet of 100 desktops from Windows…
A company is migrating its fleet of 100 desktops from Windows 10 to Windows 11. The IT department needs to enable TPM 2.0 and Secure Boot on each system via the UEFI. Some older systems have TPM disabled by default. Which UEFI setting must be changed to enable TPM?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable TPM in the UEFI security settings and set the boot mode to UEFI.
TPM (Trusted Platform Module) is often disabled by default in the UEFI firmware. It must be enabled in the security settings of the UEFI. Additionally, the system must be set to UEFI mode (not Legacy) with Secure Boot enabled for Windows 11 compatibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable TPM in the UEFI security settings and set the boot mode to UEFI.
Why this is correct
Enabling TPM in the UEFI security settings is crucial because the Trusted Platform Module, whether discrete or firmware-based, must be explicitly activated to function as a hardware root of trust. Concurrently, setting the boot mode to UEFI is essential, as it supports modern security features like Secure Boot, which often relies on TPM for platform integrity verification, a prerequisite for operating systems like Windows 11.
- ✗
Update the UEFI firmware to the latest version from the manufacturer.
Why it's wrong here
Updating the UEFI firmware to the latest version from the manufacturer can introduce support for newer hardware or features, including potentially a TPM module if it wasn't previously recognized. However, a firmware update alone does not automatically enable the TPM; it merely provides the capability. The TPM must still be manually activated within the UEFI's security settings after the update is complete.
- ✗
Disable the integrated graphics to free up resources for TPM.
Why it's wrong here
Disabling integrated graphics to 'free up resources' for the Trusted Platform Module is incorrect because TPM operates as a distinct hardware component or a firmware module within the system's security architecture. Integrated graphics, conversely, is a separate processing unit dedicated to display output. These components do not share or compete for the same system resources in a manner where disabling one would benefit the other's functionality or availability.
- ✗
Set the SATA controller to RAID mode.
Why it's wrong here
Setting the SATA controller to RAID mode primarily configures how storage drives are managed, enabling features like data striping for performance or mirroring for redundancy across multiple disks. This setting, whether RAID, AHCI, or IDE, exclusively pertains to the storage subsystem's operation and has no functional relationship or impact on the Trusted Platform Module. TPM is a security chip or firmware module entirely separate from disk controller configurations.
Go deeper
Related to this question
Learn chapter
Mobile Operating Systems: iOS and Android
Key term
UEFI
UEFI (Unified Extensible Firmware Interface) is a modern firmware interface that initializes hardware and boots the operating system, replacing the older BIOS.
Key term
TPM
TPM (Trusted Platform Module) is a dedicated hardware chip on a computer's motherboard that stores cryptographic keys, passwords, and certificates to secure the system against unauthorized access and tampering.
About these practice questions
Courseiva writes every 220-1201 question from scratch — 972 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1201 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1201 exam.