Based on the exhibit, which hardening change best prevents a laptop from booting unapproved tools from external media?
Exhibit: UEFI Setup - Secure Boot: Disabled - Boot order: USB, External NIC, Internal SSD - Firmware admin password: Not configured - BitLocker status: Enabled
Incident note: A technician confirmed the laptop was started from a USB recovery stick that bypassed the normal corporate login workflow.