Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company's security policy requires that all laptops have full-disk encryption. A technician has enabled BitLocker on a Windows 10 laptop. To ensure the recovery key is accessible if the user forgets their PIN, which action should the technician take?

⚠ Common exam trap

A common mix-up: candidates think saving the key to OneDrive is acceptable because it is 'cloud storage,' but the CompTIA 220-1102 exam emphasizes that recovery keys must be stored in a secure, centrally managed location (like AD or a network share) rather than a user-controlled personal cloud account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the recovery key in a secure network location.

Storing the BitLocker recovery key in a secure network location (e.g., Active Directory Domain Services or a dedicated key management server) ensures that authorized personnel can retrieve the key if the user forgets their PIN. This aligns with enterprise security policies that require centralized, access-controlled storage for recovery keys, preventing data loss while maintaining encryption integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Store the recovery key in a secure network location.

    Why this is correct

    Storing the recovery key in a secure, access-controlled network location is the industry-standard practice for BitLocker recovery. It ensures that the 48-digit recovery password is available only to authorized IT personnel, typically via an encrypted file share or Active Directory Domain Services, and it maintains a centralized audit trail for key retrieval. This approach separates the recovery credential from the physical device, so even if the laptop is stolen, the key remains confidential and usable for authorized recovery operations after hardware failures or TPM resets.

  • ✗

    Print the recovery key and tape it to the laptop.

    Why it's wrong here

    Taping the printed recovery key to the laptop completely negates BitLocker's encryption because any casual observer or thief can photograph or read the 48-digit key directly from the device. This effectively hands an attacker the means to unlock the volume at will, bypassing the TPM and PIN protections entirely. It violates the fundamental security principle that recovery credentials must never be co-located with the asset they protect, and it also exposes the key to every person who handles the laptop, including service technicians or cleaners.

  • ✗

    Save the recovery key in the user's OneDrive.

    Why it's wrong here

    Saving the recovery key in the user's personal OneDrive is risky because that cloud storage is often unmanaged, lacks enterprise access controls, and may not enforce strong authentication or data-loss-prevention policies. If the user's Microsoft account is compromised, or if the file is accidentally shared via a public link or synchronized to a non-compliant device, the recovery key could be exposed to unauthorized parties. Additionally, IT has no guaranteed visibility or retrieval path for the key in an unmanaged OneDrive, meaning that when the user leaves the company or loses their credentials, the recovery key could become inaccessible exactly when it is needed most.

  • ✗

    Disable the PIN requirement.

    Why it's wrong here

    Disabling the PIN requirement does not eliminate the need for a recovery key; it actually increases the risk of unauthorized access and still leaves the system vulnerable to forced recovery-mode prompts. BitLocker enters recovery mode not only after a forgotten PIN but also when the TPM detects hardware changes, boot configuration modifications, or a failed authentication, so a backup recovery key remains essential for data availability. Furthermore, removing pre-boot authentication weakens the encryption against offline attacks, because the TPM alone may automatically release the volume encryption key without requiring user credentials, making the drive trivially decryptable if the device is stolen.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.