A security administrator is implementing TPM 2.0 for secure boot and measured boot on new laptops. Which TWO capabilities does TPM 2.0 provide that are directly related to ensuring the integrity of the boot process? (Select TWO.)
Remote attestation lets the TPM sign a quote over selected PCR values, allowing a remote verifier to confirm the boot chain matched expected measurements. This satisfies the integrity-verification requirement by detecting tampering with firmware or boot components before trust is granted.
Why this answer
Option A (Remote attestation to verify boot measurements) is correct because TPM 2.0 can produce a signed quote of PCR values that a remote verifier uses to attest that the boot chain matches expected measurements, directly ensuring boot-process integrity. Option B (Platform Configuration Registers (PCRs) for storing measurements) is correct because TPM 2.0 PCRs hold the cumulative hashes of boot components (firmware, bootloader, OS) that form the basis of measured boot and are the values attested in option A. Option C is not a TPM capability; UEFI Secure Boot enforcement is performed by UEFI firmware using signature databases (db, dbx, KEK, PK), though the TPM may record its state.
Option D, sealed storage, protects encryption keys by binding them to PCR values, but it is a data-protection feature rather than a direct boot-integrity capability. Option E, RSA key generation for code signing, is a general cryptographic function and not specifically tied to ensuring boot-process integrity.