100-140 Question 251
Select 2You are troubleshooting a user's laptop that is encrypted with BitLocker. The user cannot access their system because they are prompted for a BitLocker recovery key. The user does not have the key readily available. What is the BEST course of action to retrieve the BitLocker recovery key?
- A
Check the user's Microsoft account to retrieve the recovery key.
- B
Reformat the hard drive to bypass the BitLocker encryption.
- C
Contact the IT administrator to look for the recovery key in Active Directory or Azure AD.
- D
Use a generic recovery key found online to unlock the system.
Show answer and explanation
Correct answers: A, C
Explanation
The best options for retrieving a BitLocker recovery key involve checking the user's Microsoft account or contacting the IT administrator for retrieval from Active Directory or Azure AD. These methods are secure and allow recovery without data loss. Reformatting the hard drive should only be considered as a last resort, and generic recovery keys do not exist for BitLocker.
- A. Correct.
Checking the user's Microsoft account is a valid step because recovery keys are often backed up to the connected Microsoft account during BitLocker setup.
- B. Incorrect.
Reformatting the hard drive will bypass encryption but result in complete data loss, which is not an appropriate first step for an IT support technician.
- C. Correct.
Contacting the IT administrator is correct because recovery keys are often stored in Active Directory or Azure AD in a managed IT environment.
- D. Incorrect.
Using a generic recovery key found online is not secure or feasible, as BitLocker recovery keys are unique to each system and user.