220-1101 Question 8
Single answerBiometricsA company deploys fingerprint readers on shared Windows laptops used by warehouse supervisors. Several users report that the readers frequently fail to recognize employees who have worn fingerprints from manual labor, causing delays at the start of each shift. Management wants to keep biometric sign-in in place but reduce login failures without significantly lowering security. Which action should the technician recommend?
- A
Enroll each user with multiple fingers so an alternate fingerprint can be used if one finger is difficult to scan
- B
Disable biometrics and switch all users to shared generic passwords to prevent failed fingerprint scans
- C
Lower the account lockout threshold so users can retry fingerprint authentication more times before being locked out
- D
Replace fingerprint readers with RFID proximity badges because RFID is also a biometric factor
Show answer and explanation
Correct answer: A
Explanation
The best recommendation is to enroll multiple fingers for each user. In real-world biometric deployments, fingerprint quality can vary due to occupation, skin condition, or injury. Warehouse and construction environments commonly create recognition problems because fingerprints may become worn or damaged. Using alternate enrolled fingers improves successful authentication while maintaining biometric controls. This aligns with common vendor and operating system guidance for biometric setup, including best practices seen in Windows Hello and enterprise biometric deployments: capture good-quality templates and enroll backup fingers when available. The other options either weaken security, fail to solve the actual issue, or confuse biometrics with other authentication factors.
- A. Correct.
Correct. Enrolling multiple fingers is a practical best practice for fingerprint authentication, especially for users whose primary fingerprint may be hard to read because of wear, cuts, dirt, or dry skin. This keeps biometric authentication in use while improving usability and availability without fundamentally weakening security.
- B. Incorrect.
Incorrect. Shared generic passwords would reduce accountability and weaken security. Biometrics are intended to uniquely identify or verify individual users, while shared credentials make auditing and nonrepudiation much harder.
- C. Incorrect.
Incorrect. Account lockout settings are related to repeated failed authentication attempts, but they do not address the root problem: poor fingerprint readability. Also, lockout thresholds are typically associated with password policies and do not improve biometric capture quality.
- D. Incorrect.
Incorrect. RFID proximity badges are not biometrics. They are a possession factor, not an inherence factor. While badges may be useful in some environments, this option is based on a misunderstanding of authentication factor types.