220-1102 exam dumps

220-1102 practice question 345 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 345

Single answerTime-based one-time password (TOTP)

A user can sign in to a company VPN with their username and password, but their 6-digit code from an authenticator app is rejected with a message that the code is invalid or expired. The user recently got a new smartphone and restored apps from backup. The help desk confirms the username and password are correct, and other employees are successfully using the same VPN service. What should the technician do FIRST to resolve the TOTP issue while maintaining security?

  1. A

    Disable MFA for the user and have them continue using only a password until the next device refresh

  2. B

    Verify the new phone's date, time, and time zone are set correctly and synchronized automatically

  3. C

    Ask the user to text a screenshot of the authenticator app's current code to the help desk for validation

  4. D

    Clear the VPN client cache and saved credentials on the user's laptop

  5. E

    Re-enroll the user in TOTP by issuing a new shared secret/QR code immediately, without any identity verification

Show answer and explanation

Correct answer: B

Explanation

TOTP, defined in RFC 6238, generates one-time codes from a shared secret plus the current time, typically using 30-second time steps. Because of this, clock drift or incorrect device time is one of the most common reasons a code is rejected as invalid or expired. In a real support scenario, the safest first action is to verify that the new smartphone has automatic date and time synchronization enabled and the correct time zone configured. If the issue persists after time is corrected, the next secure step is usually to verify the user's identity and then re-enroll the authenticator because some app restores do not properly transfer TOTP secrets. This aligns with common MFA troubleshooting practices and the general security principle of not weakening authentication or requesting users to disclose active authentication factors.

  • A. Incorrect.

    Incorrect. Disabling MFA reduces security and is not the first troubleshooting step for a TOTP problem. Best practice is to preserve MFA whenever possible and troubleshoot likely causes first. Temporary MFA bypass, if allowed at all, would typically require approval and compensating controls.

  • B. Correct.

    Correct. TOTP codes are time-based and depend on the device clock being accurate. If a newly restored or replaced phone has the wrong date, time, or time zone, or is not syncing automatically, valid-looking codes can be rejected as expired or invalid. Checking time synchronization is a common first step because it is low risk, fast, and often resolves TOTP failures without changing enrollment.

  • C. Incorrect.

    Incorrect. Asking users to share active one-time codes is poor security practice. Although a TOTP code is short-lived, it is still an authentication factor and should not be transmitted unnecessarily to support staff. Proper troubleshooting should avoid collecting live authentication secrets when possible.

  • D. Incorrect.

    Incorrect. Clearing the VPN client's cache or saved credentials might help with username/password or token storage issues in some products, but it does not address the most likely root cause in this scenario: a time-based code generated on a replacement phone after app restore. TOTP generation occurs on the authenticator device and relies on the shared secret and accurate time.

  • E. Incorrect.

    Incorrect. Re-enrollment may eventually be necessary if the secret did not transfer correctly during the move to the new phone, but it should not be done first and never without identity verification. Resetting or reissuing MFA factors requires confirming the user's identity according to company policy to prevent social engineering or account takeover.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam