220-1102 exam dumps

220-1102 practice question 371 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 371

Single answerPersonal identification number (PIN)

A company issues Windows 11 laptops that use TPM-backed Windows Hello PINs for sign-in. A user reports that after forgetting their PIN, they can no longer sign in with it. They still know their account password and need the fastest secure way to regain access without reimaging the laptop or weakening security. What should the technician advise the user to do?

  1. A

    At the Windows sign-in screen, choose the password sign-in option, log in with the account password, and then reset the PIN from Sign-in options in Settings

  2. B

    Boot into Safe Mode and use an administrator account to view the current PIN so the user can keep using it

  3. C

    Disable the TPM in UEFI settings, restart the laptop, and create a new PIN before re-enabling the TPM

  4. D

    Use System Restore to roll the laptop back to a point before the user forgot the PIN

Show answer and explanation

Correct answer: A

Explanation

The best answer is to have the user sign in with an alternate valid method, such as their password, and then reset the Windows Hello PIN. In Windows, a PIN is generally device-specific and is not recoverable like a stored note or visible credential. This design is part of its security value: the PIN is local to the device and can be backed by TPM protection, reducing exposure compared with relying only on a reusable password. Microsoft documentation for Windows Hello and PIN sign-in supports the idea that users can reset a forgotten PIN after authenticating through another approved method. For A+ Core 2, this tests practical identity and access troubleshooting: use the supported recovery path, avoid attempts to reveal the PIN, and do not disable security features such as TPM unless specifically required by documented remediation steps.

  • A. Correct.

    Correct. A Windows Hello PIN is tied to the device and protected by the local security hardware/software stack, commonly including the TPM. It is not meant to be recoverable in plain text. If the user still knows the account password, the appropriate process is to sign in with the password and then reset or recreate the PIN through Windows Sign-in options. This restores access quickly without bypassing security controls.

  • B. Incorrect.

    Incorrect. A technician cannot view an existing Windows Hello PIN in readable form from Safe Mode or by using an administrator account. The PIN is designed as a local authentication factor, not a retrievable secret. This option reflects the common misconception that PINs are stored in a way administrators can simply reveal.

  • C. Incorrect.

    Incorrect. Disabling the TPM is not a recommended troubleshooting step for a forgotten Windows Hello PIN. It can disrupt protected credentials and security features and may create additional access problems. The correct approach is to use an alternate allowed sign-in method, such as the account password, and then reset the PIN.

  • D. Incorrect.

    Incorrect. System Restore is intended to roll back certain system files and configuration changes, not to recover a forgotten Windows Hello PIN. It is slower, more disruptive, and unlikely to resolve the issue. Using restore points for a forgotten sign-in PIN is not standard best practice.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam