220-1102 exam dumps

220-1102 practice question 346 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 346

Single answerOne-time password/passcode (OTP)

A company requires employees to use multifactor authentication when signing in to its VPN. Several users report that their one-time passcodes from an authenticator app are being rejected, even though their usernames and passwords are correct. You verify that the VPN service is online and that the users are entering the current code shown in the app. Which action should the technician take FIRST to resolve the issue?

  1. A

    Check whether the users' mobile devices have the correct date and time synchronization

  2. B

    Disable MFA for the affected users and require only complex passwords

  3. C

    Have the users clear the VPN client cache and browser cookies

  4. D

    Replace the users' authenticator apps with SMS-based OTP for all future logins

Show answer and explanation

Correct answer: A

Explanation

This question tests practical troubleshooting of one-time passcodes in a multifactor authentication environment. In A+ Core 2 contexts, technicians are expected to recognize that many authenticator apps use TOTP, which generates codes based on a shared secret and the current time. If the device clock is out of sync, valid-looking codes will fail. Best practice is to verify device time, time zone, and automatic network time synchronization before making broader authentication changes. This aligns with common vendor guidance for authenticator applications and MFA platforms, which frequently list incorrect device time as a primary cause of OTP failure. Disabling MFA or broadly changing authentication methods should only be considered after root-cause analysis and approval under organizational security policy.

  • A. Correct.

    Correct. Time-based one-time password systems depend on the client device and the authentication server being closely synchronized in time. If a phone's clock is inaccurate or not automatically syncing with the network, the generated OTP can fall outside the acceptable time window and be rejected. Checking time synchronization is an appropriate first troubleshooting step in a real-world support scenario.

  • B. Incorrect.

    Incorrect. Disabling MFA reduces security and does not address the likely root cause of OTP rejection. Strong passwords alone do not provide the additional protection required by multifactor authentication. This option reflects a common but unsafe shortcut that violates security best practices.

  • C. Incorrect.

    Incorrect. Clearing a VPN client cache or browser cookies may help with some session or web authentication issues, but it is not the most likely cause when time-based OTP codes are consistently rejected across multiple users who are otherwise authenticating correctly. This distractor is plausible because technicians often troubleshoot cached credentials, but it is not the best first step here.

  • D. Incorrect.

    Incorrect. Switching all users to SMS-based OTP is not an appropriate first troubleshooting action and may reduce security compared with app-based authenticators. SMS can be more vulnerable to interception or SIM-swap attacks. The immediate issue is more likely related to time drift on the device, not the authenticator method itself.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam