Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

After reinstalling Windows 10, a user reports that they cannot open several files that were previously accessible. The files are stored on the local drive and appear with a yellow lock icon. What is the most likely cause?

⚠ Common exam trap

Watch out — candidates often confuse BitLocker (volume-level encryption with a silver lock icon) with EFS (file-level encryption with a yellow lock icon), leading candidates to choose BitLocker when the symptom clearly points to EFS certificate loss.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user's EFS certificate was not backed up and restored.

The yellow lock icon on files in Windows indicates that they are encrypted with the Encrypting File System (EFS). EFS ties decryption to the user's certificate and private key, which are stored in their user profile. When Windows is reinstalled, a new user profile is created with a new certificate, so without restoring the original EFS certificate and key, the previously encrypted files cannot be decrypted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The files were encrypted with BitLocker.

    Why it's wrong here

    BitLocker operates at the volume level, encrypting entire drives rather than tagging individual files, and therefore it never produces a yellow lock icon on user files. Even if BitLocker were protecting the storage, all files would be normally accessible after Windows boots and the user authenticates, unless the whole volume is explicitly locked. The per-file yellow lock overlay is the signature of an EFS-encrypted file, so BitLocker does not explain the reported symptom.

  • ✓

    The user's EFS certificate was not backed up and restored.

    Why this is correct

    EFS (Encrypting File System) binds each file's encryption key to a user certificate and private key that is stored inside the user's profile. Reinstalling Windows 10 removes that profile and its certificate unless you previously exported and backed it up, making the encrypted files permanently undecryptable without that private key. The only reliable recovery paths are restoring the exported certificate or having a designated EFS Data Recovery Agent decrypt the files on behalf of the user.

  • ✗

    The user no longer has write permissions.

    Why it's wrong here

    A yellow lock icon on a file is the Explorer overlay used specifically for EFS-encrypted files; NTFS permission problems are never indicated with that visual icon. If write permissions were the cause, the user would receive access-denied errors when trying to modify or delete, but they would still be able to open the file for reading. Because the lock icon itself is an encryption attribute, this option is unrelated to the screen the user is seeing.

  • ✗

    The hard drive partition was reformatted.

    Why it's wrong here

    If the hard drive partition had been reformatted during the Windows installation, all the user's files would have been erased because formatting rebuilds the file system metadata and destroys the directory entries. The files are still physically present on the drive—just inaccessible and marked with the yellow EFS lock—so the partition was not reformatted. This option also fails to explain the encryption icon, which is set by the file system, not by any formatting process.

Go deeper

Related to this question

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.