220-1102 Question 381
Single answerBitLockerA user brings in a Windows 11 Pro laptop that was working normally before a recent motherboard replacement. Now, at startup, the system prompts for a BitLocker recovery key before Windows will load. The user says they never changed their password and needs the quickest way to regain access without reinstalling Windows or losing data. Which action should the technician take FIRST?
- A
Use the BitLocker recovery key associated with the device, then suspend and re-enable BitLocker after confirming normal boot
- B
Disable Secure Boot in UEFI so BitLocker no longer checks for hardware changes
- C
Run Startup Repair from Windows Recovery Environment to rebuild the boot files and clear the BitLocker prompt
- D
Format the system drive and reinstall Windows because BitLocker indicates the drive is permanently locked
Show answer and explanation
Correct answer: A
Explanation
This scenario reflects normal BitLocker behavior. BitLocker Drive Encryption on supported Windows editions can use the TPM to validate the device's startup environment. Significant changes such as a motherboard replacement commonly trigger recovery mode because the TPM or measured boot values no longer match the original trusted state. The correct first step is to retrieve and enter the 48-digit BitLocker recovery key, which may be stored in the user's Microsoft account, Active Directory, Azure AD/Entra ID, or other organizational management systems depending on how the device was configured. After successful boot, best practice is to suspend BitLocker before planned firmware or hardware changes and then resume protection afterward. Microsoft documentation on BitLocker recovery and TPM-based protection supports this workflow.
- A. Correct.
Correct. BitLocker can enter recovery mode after significant hardware changes, including motherboard or TPM-related changes, because the platform validation measurements no longer match what was stored when protection was enabled. The proper first step is to obtain and enter the BitLocker recovery key for that device to unlock the drive and boot Windows. After verifying the system is functioning properly, the technician can suspend and then resume/re-enable BitLocker protection so the current hardware state is trusted again. This preserves user data and is the standard recovery workflow.
- B. Incorrect.
Incorrect. Disabling Secure Boot is not the correct first response and may actually create additional trust or startup issues. BitLocker uses TPM measurements and boot integrity checks; turning off Secure Boot does not legitimately bypass BitLocker recovery requirements. It can also reduce platform security and is not a best-practice solution for restoring access after a hardware change.
- C. Incorrect.
Incorrect. Startup Repair addresses certain boot configuration problems, but it does not remove a valid BitLocker recovery prompt caused by changed TPM or platform measurements. The issue in this scenario is not primarily corrupted boot files; it is that BitLocker is protecting the drive because the hardware environment changed. A technician must unlock the drive with the recovery key before making other repairs.
- D. Incorrect.
Incorrect. A BitLocker recovery prompt does not mean the drive is permanently inaccessible or damaged. BitLocker is designed to protect data from unauthorized access, and the recovery key exists specifically for situations like hardware replacement. Reinstalling Windows would be unnecessarily destructive and should not be the first action when data can likely be recovered by using the proper recovery key.