Courseiva
Operational Procedures →easyMultiple Choice

220-1102 Identity verification Practice Question

A help desk technician receives a call from a user who claims their password is not working. The technician asks the user to verify their identity by providing their employee ID and date of birth. The user provides this information. According to best practices for password resets, what should the technician do NEXT?

⚠ Common exam trap

It's easy for candidates to assume providing any personal information (like employee ID and date of birth) is sufficient for identity verification, but the exam tests that best practices require multiple, different authentication factors before performing a password reset.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the user's identity using a different method

Best practices for password resets require multi-factor identity verification before granting access or changing credentials. The technician has only used one method (employee ID and date of birth), which is insufficient as it relies on static, easily compromised data. The next step should be to verify the user's identity using a different method, such as a one-time passcode sent to a registered device or a knowledge-based authentication question, to ensure the request is legitimate and prevent unauthorized access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reset the password and provide the new password to the user

    Why it's wrong here

    Resetting the password and immediately providing the new password to the caller without verifying their identity effectively hands over control of the account to an unknown party. This can result in unauthorized access, data theft, or irreversible damage. Safety demands that the technician confirm the caller through a secure second channel before performing any account modifications, regardless of how urgent the request appears.

  • ✓

    Verify the user's identity using a different method

    Why this is correct

    In a password reset scenario, if the user's identity cannot be established via primary means such as knowledge-based questions, the technician should use an out-of-band verification method like sending a one-time code to a pre-registered phone number or email address. This second-factor check confirms that the caller is the legitimate account owner and defends against social engineering. Any such verification must comply with the organization's security policy to ensure consistency.

  • ✗

    Ask the user for their previous password

    Why it's wrong here

    Asking for a previous password is an unreliable verification method because that password may have been compromised, reused, or shared, and possessing it does not prove the caller is the true account holder. Moreover, security policies prohibit users from divulging passwords, and soliciting one violates those standards. A technician should never request a password; instead, they should rely on dedicated identity proofing steps.

  • ✗

    Escalate the issue to a supervisor

    Why it's wrong here

    Escalating to a supervisor before attempting standard verification is an unnecessary step that delays the user's resolution and wastes supervisory time. For routine password resets, the technician is fully authorized and expected to follow established identity verification procedures, including alternate factors. Escalation is reserved for exceptional situations such as policy exceptions, legal holds, or unresolved technical conflicts, not for typical reset requests.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.