Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company policy requires that all laptops be encrypted to protect data in case of theft. A technician enables BitLocker Drive Encryption on a Windows 10 Pro laptop equipped with a TPM 2.0 chip. After encryption completes, which of the following is the MOST secure method to protect the BitLocker recovery key?

⚠ Common exam trap

Test-takers frequently think printing the key and attaching it to the laptop is convenient and still secure, but CompTIA tests the understanding that physical co-location of the recovery key with the device completely nullifies the encryption's protection against theft.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Save the recovery key to the user's Microsoft account or Microsoft Entra ID

Saving the BitLocker recovery key to the user's Microsoft account or Microsoft Entra ID is the most secure method because it stores the key off-device in a cloud-based, access-controlled directory. This ensures the key is not physically accessible to an attacker who steals the laptop, and it can be retrieved by authorized users via secure authentication. The TPM 2.0 chip protects the encryption keys at boot, but the recovery key must be stored separately to allow access if the TPM fails or the PIN/password is lost.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Save the recovery key to the user's Microsoft account or Microsoft Entra ID

    Why this is correct

    Saving the BitLocker recovery key to the user's Microsoft account or Microsoft Entra ID is correct because the key is encrypted in transit and at rest, tied to the user's Microsoft Entra ID identity, and can be retrieved through strong authentication such as MFA. This centralizes recovery in a controlled cloud location that is physically separate from the device, aligning with Microsoft's recommended best practice for both consumer and enterprise BitLocker deployments. It also allows administrators to recover keys via the Microsoft Entra ID portal when needed, maintaining security while preserving data access.

  • ✗

    Print the recovery key and tape it to the bottom of the laptop

    Why it's wrong here

    Printing the recovery key and taping it to the bottom of the laptop is catastrophically insecure because the key is stored directly on the device it is meant to protect. Anyone who steals or finds the laptop can read the recovery key and use it to decrypt the drive, completely bypassing BitLocker's encryption. This practice violates the fundamental principle of separating the recovery key from the encrypted hardware, making it an immediate policy violation.

  • ✗

    Store the recovery key on a USB flash drive kept in the laptop carrying case

    Why it's wrong here

    Storing the recovery key on a USB flash drive kept in the laptop carrying case fails because the key and the device are transported together, so a single theft event compromises both the encrypted laptop and its decryption key. Physical separation requires the key to be kept in a different location, such as a safe or a secured network directory, not in an accessory that is commonly stolen alongside the machine. This option provides no meaningful security benefit over keeping the key inside the laptop itself.

  • ✗

    Disable the TPM so that the user must enter a pre-boot PIN instead

    Why it's wrong here

    Disabling the TPM so the user must enter a pre-boot PIN changes the authentication method but does not securely back up the BitLocker recovery key. The recovery key is still generated and must be stored somewhere for scenarios such as lost PINs, TPM hardware failure, or system component changes. Disabling the TPM may weaken platform integrity validation and fails to address the policy requirement for secure key recovery, so it does not satisfy the encryption policy.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company's security policy requires that all data on laptops be encrypted. A technician has enabled BitLocker on a laptop and saved the recovery key to the user's Microsoft account. After a motherboard failure, the laptop is replaced and the technician tries to access the old drive via a USB enclosure. The recovery key is not available because the user's Microsoft account was deleted. What could have been done to prevent this situation?

medium
  • ✓ A.Save the recovery key to a network share
  • B.Enable TPM
  • C.Use a startup PIN
  • D.Encrypt the drive with EFS instead

Why A: Saving the BitLocker recovery key to a network share provides a centralized, independent backup that is not tied to a user's Microsoft account. When the user's account was deleted, the recovery key stored in that account became inaccessible. A network share, accessible by domain credentials or a service account, would have survived the account deletion and allowed the technician to unlock the old drive via the USB enclosure.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.