How can you minimize the exposure of a spoofing PXE server?

A.
by encrypting the messages between the DHCP server, the PXE server, and the client
B.
by setting PXE last in the boot order on the server
C.
by removing support for Boot Integrity Services (BIS) from the PXE server
D.
by configuring BIS on the PXE server NICs
Explanation: