220-1102 exam dumps

220-1102 practice question 286 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 286

Single answerExternal hardware tokens

A company requires remote employees to use MFA when signing in to its VPN. One employee can enter their username and password successfully, but the login fails when they insert a USB security key and tap it. The key works on another company laptop, and the employee recently received a replacement laptop. You verify that the VPN client and user account are configured correctly. Which action should the technician take FIRST to resolve the issue?

  1. A

    Register the replacement laptop or browser with the external hardware token system so the security key can be used on that device

  2. B

    Disable MFA for the user temporarily and have them sign in with only a password

  3. C

    Replace the USB security key because it is clearly defective

  4. D

    Reset the user's VPN password and resynchronize the token seed

Show answer and explanation

Correct answer: A

Explanation

This question tests practical troubleshooting of external hardware tokens in an MFA environment. A key clue is that the USB security key works on another company laptop, which points away from token failure and toward a device-specific issue on the replacement laptop. In real environments, external hardware tokens such as USB security keys may require proper enrollment, supported browsers, enabled USB/HID access, or registration with the identity provider on the new system. Best practice is to troubleshoot the local device configuration first before replacing working hardware or weakening security controls. This aligns with standard troubleshooting methodology and with vendor guidance for hardware security keys and modern MFA deployments, where device/browser registration and compatibility are common causes of failure after hardware replacement.

  • A. Correct.

    Correct. Since the external hardware token works on another company laptop, the token itself is functional. Because the problem began after the user received a replacement laptop, the most likely issue is that the new device, browser profile, or authentication setup has not been enrolled or trusted properly for that hardware token workflow. A technician should first verify device registration, browser support, USB access permissions, and token enrollment on the replacement system.

  • B. Incorrect.

    Incorrect. Disabling MFA weakens security and is not the appropriate first troubleshooting step when there is strong evidence that the token and account are valid. Security best practices call for fixing the enrollment or configuration issue rather than bypassing a required authentication factor except under tightly controlled administrative procedures.

  • C. Incorrect.

    Incorrect. The token is not clearly defective because it works on another laptop. Replacing hardware before confirming enrollment, browser compatibility, middleware requirements, or device-specific configuration would be premature and could waste time and resources.

  • D. Incorrect.

    Incorrect. Resetting the VPN password does not address a hardware token problem when the username and password already work. Also, 'resynchronizing the token seed' applies to certain time-based OTP token scenarios, not typically to USB security keys used for challenge-response or FIDO/U2F/WebAuthn-style authentication.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam