Home » Microsoft » 70-687 » What should you do?
A company has a Windows 8.1 client computer with secure boot enabled. You install a third- party adapter with an Option ROM in the computer.
When you start the computer, it starts in the Windows Recovery Environment (Windows RE).
You need to ensure that the computer starts normally.
What should you do?
A. Configure a system boot password from the system BIOS.
B. Disable C-State configuration from the system BIOS.
C. Replace the third-party adapter with an adapter that is signed by a trusted Certificate Authority (CA).
D. Enable hardware virtualization from the system BIOS.
E. Activate the Trusted Platform Module (TPM).
Correct Answer: C
Explanation/Reference:
http://technet.microsoft.com/en-us/library/hh824987.aspx
Secure Boot Overview
Secure Boot is a security standard developed by members of the PC industry to help make sure that your PC boots using only software that is trusted by the PC manufacturer.
When the PC starts, the firmware checks the signature of each piece of boot software, including firmware drivers (Option ROMs) and the operating system. If the signatures are good, the PC boots, and the firmware gives control to the operating system.
Frequently asked questions:
Q: What happens if my new hardware isn’t trusted?
A:
Your PC may not be able to boot. There are two kinds of problems that can occur:
The firmware may not trust the operating system, option ROM, driver, or app because it is not trusted by the Secure Boot database.
Some hardware requires kernel-mode drivers that must be signed. Note: many older 32-bit (x86) drivers are not signed, because kernel-mode driver signing is a recent requirement for Secure Boot.
Q: How can I add hardware or run software or operating systems that haven’t been trusted by my manufacturer?
A:
You can check for software updates from Microsoft and/or the PC manufacturer. You can contact your manufacturer to request new hardware or software to be added to the Secure Boot database.
For most PCs, you can disable Secure Boot through the PC’s BIOS.
Q: How do I edit my PC’s Secure Boot database?
A: This can only be done by the PC manufacturer.