220-1102 Security Practice Question
A company policy requires that all sensitive data stored on laptops must be encrypted. A technician enables BitLocker on a laptop, but after a reboot, the system prompts for a recovery key. The technician suspects the TPM is not being recognized. Which pre-operating system security feature should the technician check in the BIOS/UEFI?
⚠ Common exam trap
Test-takers frequently confuse Secure Boot (which validates boot loader signatures) with TPM functionality, assuming Secure Boot must be enabled for BitLocker to work, when in fact the TPM status is the direct cause of the recovery key prompt.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trusted Platform Module (TPM) status
The TPM (Trusted Platform Module) is a hardware security chip that stores BitLocker encryption keys and validates system integrity at boot. If the TPM is disabled, deactivated, or not initialized in the BIOS/UEFI, BitLocker will fall back to requiring a recovery key on every reboot. Checking the TPM status in the BIOS/UEFI is the correct pre-operating system step to ensure the TPM is enabled and recognized.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Secure Boot
Why it's wrong here
Secure Boot validates the digital signature of bootloaders against the UEFI database, but it does not participate in BitLocker's key management or sealing. A BitLocker recovery key prompt occurs when the TPM cannot validate the system state or when the cryptographic keys are unavailable, not when Secure Boot detects an untrusted bootloader. Secure Boot and BitLocker are complementary but operate independently: Secure Boot secures the boot chain, while BitLocker relies on the TPM to release the Volume Master Key. Therefore, Secure Boot being enabled or disabled has no direct influence on the need for a recovery key.
- ✓
Trusted Platform Module (TPM) status
Why this is correct
The TPM status is the correct answer because BitLocker uses the TPM to securely store the Volume Master Key (VMK), sealing it to specific platform measurements taken during the boot process. If the TPM is disabled, reset, or the system's firmware or boot configuration changes (e.g., a BIOS update), the TPM's sealed state is invalidated, and BitLocker cannot automatically unlock the drive. As a result, Windows falls back to requiring a recovery key. Key differences from other options: the TPM is the hardware root of trust for BitLocker, while Secure Boot, BIOS passwords, and Intel SGX are not involved in key release or validation.
- ✗
UEFI BIOS password
Why it's wrong here
An UEFI/BIOS password restricts who can access the firmware setup utility or boot the system, but it does not affect TPM functionality or BitLocker's cryptographic operations. BitLocker's recovery key prompt is triggered by TPM attestation failure or absent key availability, not by the presence or absence of a firmware password. Even if a BIOS password is set, the TPM will still release the VMK if the measured boot components match. Thus, a BIOS password controls pre-boot authentication for firmware changes but is unrelated to BitLocker's recovery key mechanism.
- ✗
Intel SGX
Why it's wrong here
Intel SGX (Software Guard Extensions) creates isolated memory enclaves to protect application code and data from processes at higher privilege levels, but it is not used by BitLocker for full-disk encryption. BitLocker relies on the TPM to store and release encryption keys, not on SGX's enclave technology. SGX does not influence TPM measurements, key sealing, or boot process integrity in a way that would trigger a recovery key prompt. Consequently, SGX being disabled or faulty would have no direct effect on BitLocker's ability to unlock a drive automatically.
Go deeper
Related to this question
Learn chapter
Encryption Concepts for A+
Key term
TPM
TPM (Trusted Platform Module) is a dedicated hardware chip on a computer's motherboard that stores cryptographic keys, passwords, and certificates to secure the system against unauthorized access and tampering.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.