Courseiva
Security Architecture and EngineeringhardMultiple ChoiceObjective-mapped

CISSP Security Architecture and Engineering Practice Question

A security engineer is evaluating a system that uses a Trusted Platform Module (TPM) for secure boot. The TPM measures the boot components and stores the measurements in Platform Configuration Registers (PCRs). Which of the following is a primary security goal achieved by this process?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Ensures the boot process has not been tampered with

Measured boot ensures that each boot component's hash is extended into PCRs. The TPM can attest these measurements to a remote verifier, proving the boot integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Ensures the boot process has not been tampered with

    Why this is correct

    A Trusted Platform Module (TPM) actively measures critical boot components, including firmware, bootloaders, and operating system kernels, before they execute. These measurements are stored in Platform Configuration Registers (PCRs) and compared against known good values. If any component's measurement deviates, it indicates unauthorized modification or tampering, preventing the system from booting or alerting the user to a compromised state.

  • Provides full disk encryption

    Why it's wrong here

    While a Trusted Platform Module (TPM) can securely store encryption keys, which are essential for full disk encryption (FDE) solutions like BitLocker, its primary function in the context of secure boot is not to encrypt the disk itself. Secure boot focuses on verifying the integrity of the boot chain to ensure no unauthorized software loads, whereas FDE protects data at rest by scrambling the entire storage device.

  • Prevents all malware from executing

    Why it's wrong here

    Secure boot primarily establishes a chain of trust from the UEFI firmware up through the operating system loader, ensuring that only digitally signed and trusted software components are executed during the initial boot process. However, it does not prevent all forms of malware, particularly those that exploit vulnerabilities within the operating system or applications *after* the trusted boot process has completed, or fileless malware that operates in memory.

  • Authenticates the user during boot

    Why it's wrong here

    User authentication, which verifies the identity of an individual attempting to access the system, is a distinct security control separate from the secure boot process. Secure boot's role is to validate the integrity and authenticity of the system's boot components, ensuring the platform itself is trustworthy. It does not involve prompting a user for credentials or verifying their identity to grant access.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.