A technician is tasked with enabling BitLocker on a Windows 10 Pro system without a TPM chip. Given a scenario involving securing operating systems, what is the most secure method to enable BitLocker?
Correct Answer: Configure BitLocker with a startup key on a USB drive.
Explanation: Without a TPM, BitLocker requires an external startup key (e.g., on a USB drive) for secure encryption, as it ensures physical possession for unlocking. A password alone is less secure, installing a TPM is unnecessary, EFS is file-based and not equivalent, and a PIN via Group Policy is less secure than a USB key.
Correct Answer: Configure BitLocker with a startup key on a USB drive.
Explanation: Without a TPM, BitLocker requires an external startup key (e.g., on a USB drive) for secure encryption, as it ensures physical possession for unlocking. A password alone is less secure, installing a TPM is unnecessary, EFS is file-based and not equivalent, and a PIN via Group Policy is less secure than a USB key.