220-1102 exam dumps

220-1102 practice question 342 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 342

Single answerAuthenticator application

A user enabled multifactor authentication for the company VPN using an authenticator application on a smartphone. After replacing the phone, the user can still sign in with a username and password but cannot complete the second step because the authenticator app on the new phone does not show the VPN account. The user needs access as soon as possible. Which action should the technician take FIRST?

  1. A

    In the VPN portal, disable MFA permanently for the user so they can enroll the new phone later

  2. B

    Use the organization's documented MFA recovery process, such as a backup code or an administrator-issued temporary bypass, and then re-register the authenticator app on the new phone

  3. C

    Install a different authenticator app on the new phone because any app will automatically retrieve the old tokens from the MFA server

  4. D

    Copy the authenticator app files from the old phone's backup to the new phone to restore the one-time password seeds

Show answer and explanation

Correct answer: B

Explanation

The best first action is to follow the organization's MFA recovery procedure and then re-enroll the authenticator app on the new device. In real-world support scenarios, authenticator applications used for TOTP/HOTP-based MFA usually bind the token secret to the user's enrolled device. If the phone is replaced and the token was not transferred with a supported backup or export/import process, the user must regain access through approved fallback methods such as backup codes, hardware token alternatives, or an administrator-issued temporary bypass. After that, the technician should remove the old device registration if applicable and complete a fresh enrollment on the new phone. This aligns with common security best practices from enterprise identity providers and general MFA guidance: maintain MFA protection, use documented recovery methods, and avoid unnecessarily weakening account security.

  • A. Incorrect.

    This is incorrect because permanently disabling MFA reduces account security and is not the appropriate first response for a standard device replacement. Best practice is to use an approved account recovery or temporary access method, then re-enroll the authenticator application. A technician should avoid removing a security control longer than necessary.

  • B. Correct.

    This is correct because authenticator apps commonly store the OTP secret on the device, so a replacement phone often requires the user to recover access through backup codes, preconfigured alternate methods, or an administrator-assisted temporary bypass. After access is restored, the user should re-register the new device according to company policy. This is the standard, least-risk approach in real environments.

  • C. Incorrect.

    This is incorrect because authenticator apps do not automatically pull existing OTP secrets from the MFA server unless a specific cloud-backup or transfer feature was previously configured and supported by that app and service. Simply installing a different app will not normally restore the user's existing MFA enrollment.

  • D. Incorrect.

    This is incorrect because copying application files from a phone backup is not a reliable or supported recovery method for MFA tokens in most business environments. Authenticator secrets are typically protected by the app and operating system security model, and restoring them this way may fail or violate policy. Proper recovery should follow the organization's documented MFA reset or re-enrollment process.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam