Table 10. Secure Boot (continued)
Option Description
● Secure Boot Enable Not enabled by default
Secure Boot Mode
Changes to the Secure Boot operation mode modifies the
behavior to allow evaluation of UEFI driver signatures.
Choose one of the these options:
● Deployed Mode—Default
● Audit Mode
Expert Key Management
Allows you to enable or disable Expert Key Management.
● Enable Custom Mode
This option is not set by default.
The Custom Mode Key Management options are:
● PK—Default
● KEK
● db
● dbx
Intel Software Guard Extensions options
Table 11. Intel Software Guard Extensions
Option Description
Intel SGX Enable
This field allows you to provide a secured environment for
running code/storing sensitive information in the context of
the main operating systems.
Click one of the following options:
● Disabled
● Enabled
● Software controlled—Default
Enclave Memory Size
This option sets SGX Enclave Reserve Memory Size
Click one of the following options:
● 32 MB
● 64 MB
● 128 MB—Default
Performance
Table 12. Performance
Option Description
Multi Core Support
This field specifies whether the process has one or all cores
enabled. The performance of some applications improves with
the additional cores.
● All—Default
● 1
● 2
● 3
94 System setup