Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A remote user's Windows 10 laptop is encrypted with BitLocker and joined to Microsoft Entra ID (Azure AD). The laptop fails to boot and displays the BitLocker recovery screen, asking for the recovery key. The user does not have the recovery key and is not available to check email. The technician has access to the Microsoft Entra ID portal with Global Administrator privileges. Which of the following is the MOST appropriate method to retrieve the BitLocker recovery key?

⚠ Common exam trap

Watch out — candidates often think resetting the TPM or booting from a USB will bypass BitLocker, but BitLocker recovery is specifically designed to prevent such bypasses without the correct recovery key or recovery password.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sign in to the Microsoft Entra ID portal, locate the device, and retrieve the recovery key from the device details.

When a BitLocker-encrypted device is joined to Microsoft Entra ID, the recovery key is automatically escrowed to the Microsoft Entra ID portal under the device's object. As a Global Administrator, the technician can sign in to the Microsoft Entra ID portal, navigate to the device's details, and retrieve the 48-digit recovery key directly. This method works without user interaction and does not require physical access to the laptop.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Sign in to the Microsoft Entra ID portal, locate the device, and retrieve the recovery key from the device details.

    Why this is correct

    The correct method is to sign in to the Microsoft Entra ID portal (or Intune) and navigate to the device's record, where the BitLocker recovery key is stored in escrow. Devices that are Microsoft Entra ID joined or hybrid Microsoft Entra ID joined automatically upload their recovery key during initial BitLocker enablement, making it available to Global Administrators and Intune administrators. From the device details page, you can reveal the 48-digit recovery key without needing physical access or local credentials.

  • ✗

    Use a bootable USB to reset the TPM, then boot the laptop normally.

    Why it's wrong here

    Resetting the TPM with a bootable USB modifies the platform configuration registers that BitLocker uses to seal its encryption keys. When the TPM is reset, the existing BitLocker protector becomes invalid, and the recovery key stored in Microsoft Entra ID will no longer unlock the volume, likely causing permanent data loss or requiring a full reinstallation. The laptop is already at the recovery screen, so a TPM reset does nothing to bypass the pre-boot authentication prompt—the recovery key is still required.

  • ✗

    Sign in to a local administrator account on the laptop and turn off BitLocker.

    Why it's wrong here

    The BitLocker recovery screen appears during the pre-boot environment, before Windows 10 is loaded and before any local or domain accounts can be authenticated. Signing in to a local administrator account is impossible because the operating system has not started, and controlling the machine requires the 48-digit recovery key to decrypt the system partition. Even if the local admin password were known, it is stored in the encrypted OS volume, which is locked at this stage, creating a circular dependency.

  • ✗

    Check the user's email account for the initial BitLocker recovery key email.

    Why it's wrong here

    Relying on the user's email is impractical and insecure because recovery keys are not typically sent via email in an Microsoft Entra ID environment unless explicitly configured by an administrator with a third-party email gateway. The key may have been sent to an address the user cannot access, or it may have never been emailed at all, and email could expose sensitive key material to interception. Since the device is Microsoft Entra ID joined, the authoritative and secure repository is Microsoft Entra ID, which is always available and centrally controlled, making it the only reliable source for the recovery key.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.