easyMultiple Choice
220-1202 Practice Question: That they can no longer access their encrypted…
A user reports that they can no longer access their encrypted files after a recent password change. The files were encrypted using EFS on a Windows 10 Pro workstation. What is the most likely cause of this issue?
⚠ Common exam trap
Test-takers frequently think password changes via Ctrl+Alt+Del are safe or that EFS certificates are automatically updated, when in fact the critical step is backing up the EFS certificate before any password change to avoid permanent data loss.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user did not back up their EFS certificate before changing the password.
EFS (Encrypting File System) uses a per-user certificate that is tied to the user's password hash. When a user changes their password without first backing up the EFS certificate, the system may lose access to the private key because the certificate's master key is encrypted with the old password hash. Without a backup of the certificate and private key, the encrypted files become permanently inaccessible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user changed the password via Ctrl+Alt+Del, which invalidates the EFS certificate.
Why it's wrong here
The Ctrl+Alt+Del password change sequence is simply the standard interactive login method; it does not invalidate or revoke the EFS certificate. EFS uses a certificate whose private key is protected by the user's DPAPI master key, and a normal password change should re-encrypt that master key with the new password. If the operation fails, it is due to a bug or missing master key backup, not because the certificate itself becomes invalid.
- ✓
The user did not back up their EFS certificate before changing the password.
Why this is correct
EFS encrypts files with a symmetric File Encryption Key (FEK) that is wrapped by the user's public key, and the corresponding private key is stored under the user's password-protected master key. Without a backup of the EFS certificate, a password change can leave the master key unrecoverable, because the private key is no longer decryptable with the new password. Backing up the certificate to a .PFX file lets you re-import it after a password change, restoring access; otherwise, you may need a designated recovery agent.
- ✗
The user's account was removed from the local Administrators group during the password change.
Why it's wrong here
EFS permissions are based on the certificate and private key of the user account, not on group membership such as the local Administrators group. Even a standard user can encrypt and decrypt files with EFS, and removing a user from Administrators has no effect on their ability to access previously encrypted files. The only way to lose access is losing the private key or having the certificate deleted, not by losing administrative privileges.
- ✗
The hard drive has a hardware failure that corrupted the encrypted files.
Why it's wrong here
A hardware failure can certainly cause file corruption, but the scenario explicitly ties the access loss to a password change, making an encryption-key issue far more plausible. Hardware faults typically produce read/write errors, bad sectors, or complete device failure rather than a clean inability to decrypt still-intact encrypted files. If the hard drive were failing, the user would likely see other symptoms like crashes or file-system errors, not just a sudden EFS access problem right after changing a password.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.