220-1102 Practice Question: During a security audit, you discover that a…
During a security audit, you discover that a Windows 10 workstation has the 'Store passwords and credentials using reversible encryption' policy enabled. What is the primary security risk associated with this setting?
⚠ Common exam trap
Many candidates confuse 'reversible encryption' with 'password complexity' or 'account lockout' settings, but the core risk is the ability to decrypt stored passwords, not a performance or usability issue.
Correct answer & explanation
The 'Store passwords using reversible encryption' policy causes Windows to store passwords in a format that can be decrypted back to plaintext. This directly violates the principle of storing only hashed credentials; if the SAM database or LSASS process memory is compromised, an attacker can recover the original password, enabling lateral movement or privilege escalation.
Go deeper
Related to this question
Learn chapter
Audit Logging and Review
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.