Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A user's Windows 10 computer prompts for a BitLocker recovery key after a firmware update. The user does not remember the recovery key. The user's Microsoft account is linked to the device. What is the best action for the technician to take?

⚠ Common exam trap

Watch out — candidates often assume BitLocker recovery requires complex steps like reinstalling Windows or using TPM passwords, but the exam tests the specific knowledge that recovery keys are stored in the user's Microsoft account when the device is linked, making aka.ms/myrecoverykey the correct and simplest solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Retrieve the recovery key from the user's Microsoft account at aka.ms/myrecoverykey

BitLocker recovery keys for devices linked to a Microsoft account are automatically stored in the user's Microsoft account under the recovery key portal at aka.ms/myrecoverykey. Since the user's Microsoft account is linked to the device, the technician can log in to that account and retrieve the 48-digit recovery key to unlock the drive without data loss.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reinstall Windows to bypass BitLocker

    Why it's wrong here

    Reinstalling Windows will reformat the system partition, which permanently destroys the encrypted data and the BitLocker keys sealed in the TPM. This is not a 'bypass'—it is data-destructive recovery that loses all user files and installed applications. It should be reserved for when the drive is otherwise unbootable and the data has been backed up or deemed expendable.

  • ✓

    Retrieve the recovery key from the user's Microsoft account at aka.ms/myrecoverykey

    Why this is correct

    The correct action is to go to aka.ms/myrecoverykey from another device, sign in with the same Microsoft account that was used when BitLocker was enabled, and retrieve the 48-digit recovery key. This key is backed up to the account if the user chose that option during initial BitLocker setup. Entering this key at the recovery prompt unlocks the drive without altering any data or requiring a reinstall.

  • ✗

    Use the TPM owner password to unlock

    Why it's wrong here

    The TPM owner password is an administrative credential used to manage the TPM itself, such as clearing the TPM or changing its ownership, not to unlock BitLocker-encrypted volumes. The BitLocker recovery screen specifically requests the 48-digit recovery key, and a TPM owner password will not be recognized. Additionally, many consumer Windows 10 systems never set a TPM owner password, so this option is neither valid nor commonly available.

  • ✗

    Boot into Safe Mode and disable BitLocker

    Why it's wrong here

    Safe Mode cannot be entered before the drive is decrypted, because the BitLocker recovery screen appears during the pre-boot environment, before Windows loads. Without the recovery key, the system remains locked, so you cannot access Safe Mode to disable BitLocker. Attempting to boot into Safe Mode first would still require the recovery key, making this approach circular and ineffective.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.