Your organization already uses MBAM to escrow BitLocker recovery keys for Windows clients. After a recent incident, you must enable automatic unlock of OS volumes when domain-joined systems boot on a trusted wired network, and you want to accelerate encryption during imaging. What should you do? Choose two actions.
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy Windows Deployment Services (WDS) on a server and add the BitLocker Network Unlock feature; ensure DHCP is reachable on the same network., Issue a Network Unlock certificate from AD CS and install it on the WDS server hosting Network Unlock; configure the GPO to allow TPM+PIN with Network Unlock..
Why this is the answer
To enable automatic unlock of OS volumes on a trusted wired network, you need to deploy the BitLocker Network Unlock feature, which relies on Windows Deployment Services (WDS). WDS provides the PXE boot environment necessary for clients to communicate with the Network Unlock server. DHCP is essential for clients to obtain IP addresses and locate the WDS server. A Network Unlock certificate, issued by Active Directory Certificate Services (AD CS) and installed on the WDS server, authenticates the server to the clients. The Group Policy Object (GPO) must be configured to allow Network Unlock, often in conjunction with TPM+PIN protectors, to enable this functionality. Replacing MBAM with Microsoft Endpoint Manager is not required for Network Unlock functionality, as MBAM can continue to manage recovery keys. While pre-provisioning BitLocker can accelerate encryption, it doesn't directly enable Network Unlock or address the requirement for automatic unlock on a trusted network.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed