220-1102 exam dumps

220-1102 practice question 68 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 68

Single answerBitLocker

A company laptop running Windows 11 Pro is protected with BitLocker on the system drive. After a recent motherboard replacement, the user reports that the laptop now boots to the BitLocker recovery screen and asks for a recovery key every time it starts. The user can successfully enter the recovery key and log in to Windows. Which action should a technician take to restore normal startup while keeping BitLocker protection enabled?

  1. A

    Turn off BitLocker, decrypt the drive, and leave it unencrypted to prevent future recovery prompts

  2. B

    Suspend BitLocker, clear and reinitialize the TPM if needed, then resume BitLocker protection after Windows starts normally

  3. C

    Convert the system drive from NTFS to exFAT so BitLocker can rebuild its boot configuration

  4. D

    Disable Secure Boot permanently because BitLocker cannot work with firmware changes

  5. E

    Run Startup Repair from Windows Recovery Environment to remove the BitLocker recovery requirement

Show answer and explanation

Correct answer: B

Explanation

BitLocker uses TPM-based protectors to verify platform integrity during startup. When major hardware changes occur, especially motherboard replacement, the TPM identity and measured boot values can change, causing BitLocker to require the recovery key. Best practice is to suspend BitLocker before planned firmware or hardware work; if that was not done, the technician should use the recovery key to boot Windows, then address the TPM/BitLocker trust relationship and resume protection. On Windows Pro and Enterprise editions, BitLocker management commonly involves TPM initialization and protector updates rather than disabling encryption. Microsoft documentation on BitLocker recovery and TPM-based protection explains that hardware, firmware, or boot environment changes can trigger recovery and that suspension of BitLocker is the appropriate step before such maintenance.

  • A. Incorrect.

    This is incorrect because leaving the drive unencrypted removes the data-at-rest protection BitLocker is intended to provide. Although decrypting and re-encrypting can sometimes be part of deeper remediation, the scenario asks how to restore normal startup while keeping BitLocker enabled. The repeated recovery prompt after a motherboard replacement is commonly related to TPM measurements and trust changes, not a requirement to permanently disable encryption.

  • B. Correct.

    This is correct. BitLocker commonly enters recovery after significant hardware or firmware changes, such as a motherboard replacement, because the TPM no longer matches the platform measurements used to unlock the drive automatically. Suspending BitLocker temporarily allows maintenance without triggering protection, and clearing/reinitializing the TPM when appropriate can help establish trust with the new hardware. After the system boots normally, resuming BitLocker re-enables standard protection.

  • C. Incorrect.

    This is incorrect because BitLocker system drives require NTFS; converting the OS volume to exFAT is not a valid fix and would break normal Windows boot requirements. This distractor reflects a misconception that file system changes can repair BitLocker trust issues. The problem is tied to TPM and platform validation, not the file system format.

  • D. Incorrect.

    This is incorrect because BitLocker is designed to work with Secure Boot and TPM-based protection. Firmware or hardware changes can trigger recovery, but permanently disabling Secure Boot is not the standard fix and can reduce platform security. A technician should address the trust relationship and BitLocker protector state instead of weakening firmware protections.

  • E. Incorrect.

    This is incorrect because Startup Repair is intended for boot configuration and startup file problems, not for TPM validation changes that cause BitLocker recovery mode. Since the user can already unlock the drive with the recovery key and access Windows, the boot files are likely functional. The issue is automatic unlock during startup, not a corrupted boot loader.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam