What should you do to prevent a potential hacker from booting to a USB drive on a Windows workstation?

A Set a BIOS/UEFI password.

Change the default administrator password, use a strong Windows password, and restrict access using user permissions to protect Windows. However, these acts do not protect the computer as a whole. A user can change the boot sequence, boot to an USB drive, and cause some system damage if they can access the BIOS/UEFI (Basic Input Output System/Unified Extensible Firmware Interface). The solution is to use a BIOS/UEFI password to protect against this.

