220-1102 Security Practice Question
A company's security policy requires that all data on laptops be encrypted. A technician has enabled BitLocker on a laptop and saved the recovery key to the user's Microsoft account. After a motherboard failure, the laptop is replaced and the technician tries to access the old drive via a USB enclosure. The recovery key is not available because the user's Microsoft account was deleted. What could have been done to prevent this situation?
⚠ Common exam trap
Many exam-takers assume TPM or a startup PIN provides recovery capability, but these are pre-boot authentication mechanisms that do not generate or store a recovery key; the recovery key must be saved externally to be usable after hardware replacement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Save the recovery key to a network share
Saving the BitLocker recovery key to a network share provides a centralized, independent backup that is not tied to a user's Microsoft account. When the user's account was deleted, the recovery key stored in that account became inaccessible. A network share, accessible by domain credentials or a service account, would have survived the account deletion and allowed the technician to unlock the old drive via the USB enclosure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Save the recovery key to a network share
Why this is correct
Saving the BitLocker recovery key to a network share (or to Active Directory for domain-joined laptops) is the only option that ensures an independent, centrally managed backup of the 48-digit recovery key. This guarantees that IT can always retrieve the key to unlock the drive, even if the user's Microsoft account is deleted, the TPM fails, or the laptop is moved to a different system. In a corporate environment, the security policy requiring all laptop data to be encrypted also demands that recovery keys be escrowed so that data isn't permanently lost if a local key copy is unavailable.
- ✗
Enable TPM
Why it's wrong here
TPM (Trusted Platform Module) is used to store BitLocker encryption keys and provide hardware-level security, but it does not provide a recovery key backup. The recovery key is still needed for scenarios like failed hardware.
- ✗
Use a startup PIN
Why it's wrong here
A startup PIN (or enhanced PIN) adds an additional authentication factor before BitLocker unlocks, but it does not affect the recovery key backup. It also does not help when the drive is moved to a different system.
- ✗
Encrypt the drive with EFS instead
Why it's wrong here
EFS (Encrypting File System) encrypts only selected files and folders, not the entire volume, so it cannot satisfy a policy that requires all data on the laptop to be encrypted. Additionally, EFS recovery relies on a Data Recovery Agent (DRA) and stores keys in the user's profile, which does not provide the same full-disk, pre-boot protection as BitLocker and introduces its own recovery complications when users or profiles change. Choosing EFS instead of BitLocker would leave the operating system files, pagefile, and unselected user data unprotected, making it an ineffective substitute for full-volume encryption.
Go deeper
Related to this question
Learn chapter
Data Sanitization: Wipe, Degauss, Shred, Incinerate
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.