220-1102 Security Practice Question
A technician is supporting a clinic workstation. The immediate goal is to unlock an encrypted Windows drive after security-state change. Which tool, control, or procedure is the best fit?
⚠ Common exam trap
Watch out — candidates often confuse BitLocker recovery with password reset or system repair tools, assuming System Restore or Event Viewer can resolve encryption lockouts, when in fact only the recovery key can bypass the TPM's security check.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker recovery key
When a Windows system's security state changes (e.g., TPM reset, motherboard replacement, or boot configuration alteration), BitLocker enters recovery mode and requires the 48-digit recovery key to unlock the encrypted drive. This key is generated during BitLocker setup and can be stored in Active Directory, a Microsoft account, or printed. Using the recovery key is the only supported method to regain access without data loss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
BitLocker recovery key
Why this is correct
The BitLocker recovery key is a 48-digit numeric key generated when BitLocker is enabled. It's the only credential that can unlock a BitLocker-protected volume when the normal startup process fails, such as after a TPM change or BIOS update. For a locked clinic workstation, entering this key at the recovery console directly restores access, making it the immediate solution.
- ✗
Local Users and Groups
Why it's wrong here
Local Users and Groups is a management console for creating and modifying user accounts and group memberships on a local machine. It does not interact with BitLocker's encryption layer because BitLocker locks the entire volume before the operating system and its user management tools load. While it might help reset a Windows password, it cannot unlock a BitLocker-encrypted drive.
- ✗
System Restore
Why it's wrong here
System Restore rolls back Windows system files, registry settings, and installed applications to a prior restore point. It operates within a booted Windows environment and does not affect BitLocker's pre-boot encryption lock. When a workstation is stuck at the BitLocker recovery screen, System Restore is inaccessible and irrelevant because the volume isn't mounted.
- ✗
Event Viewer
Why it's wrong here
Event Viewer is a diagnostic tool that displays application, security, and system logs, which can help identify why a system misbehaved. It has no mechanism to decrypt or unlock a BitLocker-protected volume, and in a recovery lockout scenario, the event logs are typically unavailable until the drive is unlocked. It might be used later for troubleshooting, but it cannot achieve the immediate goal.
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
Key term
TPM
TPM (Trusted Platform Module) is a dedicated hardware chip on a computer's motherboard that stores cryptographic keys, passwords, and certificates to secure the system against unauthorized access and tampering.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.