220-1102 exam dumps

220-1102 practice question 517 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 517

Single answerPolicies and procedures

A technician receives a call from someone claiming to be the CFO, who says they are traveling and urgently need the password reset for their corporate email account. The caller provides the CFO's employee ID and says there is no time to wait for normal verification because a board meeting starts in 10 minutes. Company policy requires identity verification before any credential changes. What should the technician do FIRST?

  1. A

    Reset the password immediately because the caller provided an employee ID and the request is time-sensitive

  2. B

    Refuse to help and tell the caller to contact the help desk again during normal business hours

  3. C

    Follow the organization's identity verification procedure before making any account changes, and escalate according to policy if urgent access is needed

  4. D

    Ask the caller for their manager's name and reset the password if the name matches the directory

Show answer and explanation

Correct answer: C

Explanation

This question tests the application of policies and procedures in a social engineering scenario, which is a common A+ Core 2 objective area. When handling password resets or other account changes, technicians should use only approved identity verification methods and should not be influenced by urgency, job title, or pressure from the caller. Executive impersonation is a well-known tactic in social engineering attacks. Best practice is to follow the documented process for verification and, if necessary, use the organization's escalation path for urgent exceptions rather than creating an informal workaround. This reflects standard security guidance found in help desk procedures, acceptable use and account management policies, and general security frameworks that emphasize verification, documentation, and least privilege.

  • A. Incorrect.

    This is incorrect. An employee ID alone is not sufficient proof of identity for a password reset. Attackers often use publicly available or stolen details to impersonate executives. Bypassing verification because the request feels urgent is a classic social engineering trap and violates standard security policy.

  • B. Incorrect.

    This is incorrect. The technician should not simply refuse assistance if there is a legitimate urgent business need. The correct response is to follow the documented verification and escalation process. Policies and procedures are designed to allow secure handling of urgent situations without skipping required controls.

  • C. Correct.

    This is correct. For credential changes, the technician should follow the approved identity verification process exactly as documented. If the user cannot complete normal verification and the situation is truly urgent, the technician should escalate through approved channels rather than bypass policy. This aligns with common security best practices for account management, least privilege, and resisting social engineering.

  • D. Incorrect.

    This is incorrect. Knowing a manager's name is weak verification because that information is often easy to find internally or on professional networking sites. Using informal or ad hoc verification methods increases the risk of unauthorized access and does not satisfy policy requirements for sensitive account actions.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam