Courseiva
mediumMultiple Choice

220-1202 Practice Question: A helpdesk technician receives a call from an…

A helpdesk technician receives a call from an employee who says their smart card stopped working for building access. The employee is in a hurry and asks the technician to remotely disable the card and issue a temporary PIN for the day. What should the technician do first?

⚠ Common exam trap

Test-takers frequently assume the helpdesk has full control over all credential types (logical and physical) and can perform remote operations on smart cards, when in fact physical access systems are usually separate and require in-person identity verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ask the employee to visit the security office in person with a photo ID.

Smart card credentials for physical access are typically managed by a separate physical security system (e.g., an access control server), not the helpdesk's IT identity management system. The technician cannot remotely disable the card or issue a temporary PIN without proper authorization and verification of the caller's identity. The standard procedure is to require in-person verification with a photo ID at the security office to prevent social engineering attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the smart card and provide a temporary PIN as requested.

    Why it's wrong here

    Complying immediately grants building access based solely on a phone request, bypassing the identity verification that must precede disabling a card and issuing a PIN. Fulfilling such requests is normal once the caller's identity is confirmed through established helpdesk procedures.

  • ✓

    Ask the employee to visit the security office in person with a photo ID.

    Why this is correct

    Smart card issuance and PIN reset are high-risk identity operations requiring in-person identity proofing. Verifying the employee's photo ID at the security office prevents an attacker from social-engineering a card disablement or temporary credential over the phone.

  • ✗

    Reset the smart card remotely and test it with a badge reader.

    Why it's wrong here

    Resetting the card and testing it destroys the evidence needed to determine whether the fault is the card, reader or access system, and remote resetting exceeds the technician's authority. It is tempting because resetting a card is the standard fix once a fault has been properly diagnosed.

  • ✗

    Send a temporary PIN via email to the employee's company address.

    Why it's wrong here

    Emailing a PIN to a company address authenticates nothing about the caller, so a stolen card could be paired with a PIN sent to an unverified recipient. Email delivery suits routine credential distribution, but this scenario demands identity verification before any access credential is released.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.