Courseiva
easyMultiple Choice

220-1202 Practice Question: During a security audit, you discover that a…

During a security audit, you discover that a Windows 10 workstation has the 'Store passwords and credentials using reversible encryption' policy enabled. What is the primary security risk associated with this setting?

⚠ Common exam trap

Many candidates confuse 'reversible encryption' with 'password complexity' or 'account lockout' settings, but the core risk is the ability to decrypt stored passwords, not a performance or usability issue.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It stores passwords in a format that can be easily decrypted, making them vulnerable if the database is compromised.

The 'Store passwords using reversible encryption' policy causes Windows to store passwords in a format that can be decrypted back to plaintext. This directly violates the principle of storing only hashed credentials; if the SAM database or LSASS process memory is compromised, an attacker can recover the original password, enabling lateral movement or privilege escalation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It increases the time required to log on to the system.

    Why it's wrong here

    Reversible encryption primarily impacts how passwords are stored, not the computational overhead of authenticating a user. The decryption process during logon is typically very efficient and does not introduce a significant delay that would noticeably increase the time required to log on to the system. Therefore, any performance impact on logon speed would be negligible compared to the severe security risks involved.

  • ✗

    It allows users to bypass the password complexity requirement.

    Why it's wrong here

    Password complexity requirements are enforced by the operating system or application at the point of password creation or modification, *before* the password is stored. Reversible encryption merely dictates the format in which the password data is saved, not the initial validation rules applied to it. Consequently, this storage method has no bearing on whether a user can bypass established complexity policies.

  • ✓

    It stores passwords in a format that can be easily decrypted, making them vulnerable if the database is compromised.

    Why this is correct

    Storing passwords using reversible encryption means the original plaintext password can be mathematically recovered from its stored form. If an attacker successfully compromises the system's password database, they can easily decrypt all stored credentials, exposing actual user passwords. This critical vulnerability allows for widespread credential stuffing attacks and unauthorized access to other services where users might reuse their passwords.

  • ✗

    It prevents the use of biometric authentication methods.

    Why it's wrong here

    Biometric authentication methods, such as fingerprint or facial recognition, operate by comparing a user's live biometric data against a securely stored template. This process is entirely independent of how traditional text-based passwords are encrypted or stored within the system. Reversible encryption of passwords does not interfere with or prevent the implementation and use of biometric verification mechanisms.

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.