Question 1
A financial services company is deploying a new fleet of PowerEdge R860 servers for a mission-critical database application. To comply with strict internal security policies, the Chief Security Officer mandates that no configuration changes can be made to the BIOS, iDRAC, or PERC controller after the initial setup, even by administrators with root privileges, until the policy is explicitly disabled. Which PowerEdge security feature must be enabled to enforce this requirement?
Answer and explanation
Correct answer: C
System Lockdown Mode is a specific feature in PowerEdge servers designed to prevent unintentional or malicious changes to the server's configuration. When enabled, it locks down system firmware settings, including BIOS, iDRAC, and controller configurations, preventing modifications until the mode is disabled. Secure Boot ensures the integrity of the bootloader, Silicon Root of Trust validates firmware cryptographically, and TPM is used for storing cryptographic keys, but only System Lockdown directly prevents configuration changes.