220-1102 exam dumps

220-1102 practice question 501 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 501

Single answerPIN codes

A user in a company managed with Microsoft 365 and Windows 11 reports that they can no longer sign in to their laptop with their Windows Hello PIN after returning from vacation. They know their Microsoft 365 password and can use it to access web apps from another device. As the technician, you need to restore access as quickly as possible without weakening security. Which action should you recommend first?

  1. A

    Use the "I forgot my PIN" option from the Windows sign-in screen to reset the Windows Hello PIN after verifying the user's identity

  2. B

    Disable Windows Hello requirement in Local Security Policy so the user can create a shorter PIN later

  3. C

    Clear the TPM in UEFI/BIOS immediately, then have the user recreate the PIN at next sign-in

  4. D

    Reset the user's Microsoft 365 password because the Windows Hello PIN is synchronized directly with the cloud password

Show answer and explanation

Correct answer: A

Explanation

The best first action is to reset the Windows Hello PIN using the supported recovery option. In Windows, a PIN is not the same as the user's account password and is not simply synced as a reusable cloud credential. It is device-specific and designed to work with local protections, often including the TPM. Best practice is to use the standard PIN reset workflow rather than weakening policy settings or taking invasive actions like clearing the TPM. Microsoft documentation on Windows Hello states that the PIN is local to the device and that users can reset it through "I forgot my PIN" when appropriate. This makes option 1 the fastest and most secure response in a real support scenario.

  • A. Correct.

    Correct. A Windows Hello PIN is tied to the specific device and protected locally, typically with TPM-backed keys. If the user knows their account password but the PIN no longer works, the recommended first step is to use the built-in PIN reset process such as "I forgot my PIN" from the sign-in screen or Settings, depending on access state. This preserves security and follows Microsoft's intended recovery workflow.

  • B. Incorrect.

    Incorrect. Lowering or disabling Windows Hello-related security settings is not the appropriate first response and weakens the organization's security posture. PIN complexity and Hello requirements are normally controlled by policy for a reason. The goal is to restore access through approved recovery steps, not bypass security controls.

  • C. Incorrect.

    Incorrect. Clearing the TPM is a disruptive step that can affect stored keys and other protections such as BitLocker, depending on configuration. It is not a first-line troubleshooting action for a forgotten or malfunctioning Windows Hello PIN. A technician should use standard PIN recovery methods before considering hardware security changes.

  • D. Incorrect.

    Incorrect. A common misconception is that a Windows Hello PIN is just another version of the user's Microsoft 365 or Microsoft account password. In reality, the PIN is local to the device and unlocks credentials or keys stored on that device. Resetting the cloud password may be necessary for password issues, but it does not directly reset the Windows Hello PIN.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam