220-1102 Security Practice Question
A user has forgotten the BitLocker recovery key for their Windows 10 laptop and is unable to boot after a BIOS update. The laptop is protected by BitLocker Drive Encryption. The user stored the recovery key in a safe, but the safe is inaccessible during a disaster. What is the BEST first step for the technician to attempt?
⚠ Common exam trap
It's easy for candidates to assume a BIOS update corrupts the OS or requires data recovery, when in fact the issue is a TPM validation mismatch that can be fixed by restoring BIOS settings, not by accessing the recovery key or reinstalling Windows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restore the previous BIOS settings
A BIOS update can change the TPM (Trusted Platform Module) configuration or clear the TPM's endorsement key, causing BitLocker to require the recovery key. Restoring the previous BIOS settings often reverts the TPM state to a known configuration, allowing the system to boot normally without needing the recovery key. This is the least disruptive first step and does not require accessing the safe or performing data recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a system restore to a point before the BIOS update
Why it's wrong here
System Restore is a Windows-level feature that rolls back system files, registry keys, and installed programs to an earlier restore point, but it cannot modify the UEFI/BIOS firmware or the TPM platform configuration registers (PCRs) that measure the boot environment. Because the BitLocker recovery prompt was triggered by a BIOS update that changed those firmware measurements, restoring the Windows system state does not alter the PCR values and cannot get the laptop past the pre-boot recovery screen.
- ✗
Remove the hard drive and connect it to another computer to retrieve data
Why it's wrong here
Physically removing the encrypted hard disk and attaching it to another computer does not bypass BitLocker; the volume is encrypted and the original laptop's TPM cannot authenticate the new hardware. The other machine will show the drive as locked and prompt for the 48-digit recovery key, or it may fail to mount the volume entirely. This is possible as a later data-recovery tactic only after the recovery key is obtained, so it does nothing to solve the immediate boot problem and adds risk of further complication.
- ✓
Restore the previous BIOS settings
Why this is correct
Reverting the UEFI/BIOS to its prior firmware version or exact previous settings restores the same boot configuration that the TPM measured during the last successful unlock, causing the measured PCR values to match what Windows expects. BitLocker's default TPM-only protection releases the encryption key automatically only when the current boot measurements match the stored ones. Once the firmware is rolled back, the system should boot normally without demanding the recovery key.
- ✗
Run the BitLocker repair tool from Windows Recovery Environment
Why it's wrong here
The BitLocker repair tool, repair-bde, is designed to recover data from a corrupted encrypted volume by decrypting it to another volume; it cannot unlock a system volume in place at boot. It also still requires the recovery key or an unlock password to access the encrypted data, so it provides no help when the key is forgotten. Moreover, it does not address the root cause—the TPM measurements changed by the BIOS update—so it would not prevent the recovery screen from reappearing.
Go deeper
Related to this question
Learn chapter
Data Destruction and Disposal
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
Key term
BitLocker
BitLocker is a full-disk encryption feature built into Windows that protects data by encrypting the entire drive so that unauthorized users cannot access files without the correct recovery key.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.