Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A user has forgotten the BitLocker recovery key for their Windows 10 laptop and is unable to boot after a BIOS update. The laptop is protected by BitLocker Drive Encryption. The user stored the recovery key in a safe, but the safe is inaccessible during a disaster. What is the BEST first step for the technician to attempt?

⚠ Common exam trap

It's easy for candidates to assume a BIOS update corrupts the OS or requires data recovery, when in fact the issue is a TPM validation mismatch that can be fixed by restoring BIOS settings, not by accessing the recovery key or reinstalling Windows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restore the previous BIOS settings

A BIOS update can change the TPM (Trusted Platform Module) configuration or clear the TPM's endorsement key, causing BitLocker to require the recovery key. Restoring the previous BIOS settings often reverts the TPM state to a known configuration, allowing the system to boot normally without needing the recovery key. This is the least disruptive first step and does not require accessing the safe or performing data recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform a system restore to a point before the BIOS update

    Why it's wrong here

    System Restore is a Windows-level feature that rolls back system files, registry keys, and installed programs to an earlier restore point, but it cannot modify the UEFI/BIOS firmware or the TPM platform configuration registers (PCRs) that measure the boot environment. Because the BitLocker recovery prompt was triggered by a BIOS update that changed those firmware measurements, restoring the Windows system state does not alter the PCR values and cannot get the laptop past the pre-boot recovery screen.

  • ✗

    Remove the hard drive and connect it to another computer to retrieve data

    Why it's wrong here

    Physically removing the encrypted hard disk and attaching it to another computer does not bypass BitLocker; the volume is encrypted and the original laptop's TPM cannot authenticate the new hardware. The other machine will show the drive as locked and prompt for the 48-digit recovery key, or it may fail to mount the volume entirely. This is possible as a later data-recovery tactic only after the recovery key is obtained, so it does nothing to solve the immediate boot problem and adds risk of further complication.

  • ✓

    Restore the previous BIOS settings

    Why this is correct

    Reverting the UEFI/BIOS to its prior firmware version or exact previous settings restores the same boot configuration that the TPM measured during the last successful unlock, causing the measured PCR values to match what Windows expects. BitLocker's default TPM-only protection releases the encryption key automatically only when the current boot measurements match the stored ones. Once the firmware is rolled back, the system should boot normally without demanding the recovery key.

  • ✗

    Run the BitLocker repair tool from Windows Recovery Environment

    Why it's wrong here

    The BitLocker repair tool, repair-bde, is designed to recover data from a corrupted encrypted volume by decrypting it to another volume; it cannot unlock a system volume in place at boot. It also still requires the recovery key or an unlock password to access the encrypted data, so it provides no help when the key is forgotten. Moreover, it does not address the root cause—the TPM measurements changed by the BIOS update—so it would not prevent the recovery screen from reappearing.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.