Configure file and disk encryption Flashcards
TPM
Trusted platform module
Cryptography specification and name of the chip used in PC hardware to allow for Bitlocker
Bitlocker is available in what editions of Windows desktop
Windows Vista / 7 Ultimate
Windows Vista / 7 Enterprise
Windows Pro 8
Windows Enterprise 8
First server version to have bitlocker
Server 2008
FDE
Full Disk Encryption
Bitlocker
software-based full disk encryption data-protection security features.
Bitlocker is available in what editions of Server 2012
All of them
Bitlocker To Go
Data on a USB device is encrypted.
Bitlocker exe is put on the drive and requires a password to access the data on the drive.
Five Bitlocker implementation
TPM USB TPM+USB TPM+PIN TPN+PIN+USB
Note that this means Bitlocker does not need a TPM chip to store a trusted key. You can use the USB instead
TPM chip does what for Bitlcoker
Preboot execution security
Confirms that hardware has not been tampered with
Confirms that files were not accessed while PC was off
USB instead of TPM for Bitlocker
You must always have the USB plugged in, to even turn on…
You can simulate the TPM chip with the USB device.
One downside: You can’t detect system integrity / confirm there was no hardware tampering, or that files weren’t accessed from the HD while the PC was off.
Recovery Key
Optional key to use in the event that you lose the TPM chip (hardware failure) or the USB or any other requirement (PIN) to boot.
For emergencies.
Can be password, key stored on USB, can be printed, or distributed via Group Policy
BL requirements to use TPM
TPM 1.2 or 2.0
TCG-compliant BIOS or UEFI firmware
Support for USB mass storage devices
separate partition on the drive just for data that’s encrypted.
EPS
Encrypted File System
Allows users to right-click a file , open properties, and encrypt files / folders.
Add-BitLockerKeyProtector
Adds a key protector for a BitLocker volume.
Backup-BitLockerKeyProtector
Saves a key protector for a BitLocker volume in AD DS.
Clear-BitLockerAutoUnlock
Removes BitLocker automatic unlocking keys.
Disable-BitLocker
Disables BitLocker encryption for a volume.
Disable-BitLockerAutoUnlock
Disables automatic unlocking for a BitLocker volume.
Enable-BitLocker
Enables encryption for a BitLocker volume.
Enable-BitLockerAutoUnlock
Enables automatic unlocking for a BitLocker volume.
Get-BitLockerVolume
Gets information about volumes that BitLocker can protect.
Lock-BitLocker
Prevents access to encrypted data on a BitLocker volume.
Remove-BitLockerKeyProtector
Removes a key protector for a BitLocker volume.
Resume-BitLocker
Restores Bitlocker encryption for the specified volume.