220-1102 Security Practice Question
A company enforces BitLocker full disk encryption on all laptops. A user forgets their BitLocker password and is unable to provide the recovery key. The laptop is domain-joined and the user has administrative credentials. Which of the following is the BEST action for the technician to take to regain access to the data?
⚠ Common exam trap
Many candidates confuse resetting the TPM with a method to bypass BitLocker authentication, not realizing that TPM reset destroys the key protector and requires the recovery key to regain access, making it a destructive action rather than a recovery solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Retrieve the recovery key from Active Directory
BitLocker recovery keys for domain-joined computers are automatically backed up to Active Directory Domain Services (AD DS) when configured via Group Policy. A technician with appropriate administrative credentials can retrieve the 48-digit recovery key from the AD DS 'BitLocker Recovery' attribute of the computer object, allowing decryption of the drive without the user's password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Retrieve the recovery key from Active Directory
Why this is correct
In domain-managed environments, BitLocker recovery keys are backed up to Active Directory by default via Group Policy. A technician with appropriate AD permissions can retrieve the 48-digit numeric recovery password from the computer object's BitLocker Recovery Information property. Using this key unlocks the encrypted drive without altering existing data or protection mechanisms.
- ✗
Reset the Trusted Platform Module (TPM)
Why it's wrong here
Resetting the TPM clears the Endorsement Key and all keys sealed to the TPM, including the BitLocker TPM protector. This invalidates the secure boot-time validation, so the drive can no longer be automatically unlocked. Without a separate recovery key, resetting the TPM will not grant data access—instead, it strips away the hardware-based key release, potentially leaving the volume permanently locked.
- ✗
Use the user's Microsoft account to retrieve the key
Why it's wrong here
The Microsoft account recovery method applies to consumer devices where BitLocker recovery keys are saved to the user's Microsoft account during initial setup. On a company-issued, domain-joined laptop, Group Policy typically mandates recovery key backup to Active Directory and may disable saving to Microsoft accounts entirely. Even if the user's Microsoft account contains a key, it would not match this corporate volume unless the device was specifically configured to use that external backup.
- ✗
Reinstall Windows and accept data loss
Why it's wrong here
Reinstalling Windows via recovery or installation media formats the system partition, destroying the encrypted file system and the data it contains. This is an irreversible, last-resort action after all non-destructive recovery methods, such as using the recovery key or accessing the Windows Recovery Environment, have failed. It does not decrypt BitLocker; it erases the volume, so data loss is certain unless a separate backup exists.
Go deeper
Related to this question
Learn chapter
Data Classification Levels
Key term
Recovery key
A recovery key is a unique code or physical device used to regain access to an encrypted system or account when the primary authentication method, such as a password or biometric, is lost or unavailable.
Key term
Group Policy
Group Policy is a Windows-based feature that allows administrators to centrally manage and enforce settings for users and computers across an organization.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.