Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A help desk technician receives a call from a user who states they forgot their password and need it reset. The technician follows the company's standard operating procedure for password resets. After successfully resetting the password and confirming the user can log in, what should the technician do NEXT according to best practices?

⚠ Common exam trap

Test-takers frequently confuse operational procedures with technical troubleshooting steps, assuming that clearing cached credentials or updating a SID is a required follow-up, when in fact documentation is the mandated next step per CompTIA's operational procedures domain.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the incident and actions taken in the ticketing system

After completing a password reset, the technician must document the incident and actions taken in the ticketing system to maintain an audit trail, comply with ITIL best practices, and ensure accountability. This documentation supports future troubleshooting, compliance audits, and helps identify recurring issues. Without proper documentation, the password reset is not considered complete from an operational procedures standpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Document the incident and actions taken in the ticketing system

    Why this is correct

    Documenting the incident and actions taken in the ticketing system is a mandatory step in IT service management. It creates an immutable audit trail that satisfies compliance, enables trend analysis, and provides a reference for future troubleshooting. Without a ticket update, the request remains unresolved from a workflow perspective, and the technician has no verifiable record that the reset was performed, identity was verified, or any follow-up was attempted.

  • ✗

    Inform the user's manager about the password reset

    Why it's wrong here

    Informing the user's manager about a routine password reset is not a standard ITIL or help desk practice, and it can violate privacy expectations or expose sensitive credential-history information. Unless the account belongs to a privileged role or an explicit organizational policy mandates manager notification for access changes, doing so adds unnecessary communication overhead and potentially exposes account details to an unauthorized party. The reset should be handled solely between the technician and the user, with the ticketing system as the official record of the action.

  • ✗

    Clear the user's cached credentials on the workstation

    Why it's wrong here

    Clearing the user's cached credentials on the workstation is unnecessary after a password reset because cached credentials are stored only for offline domain logon scenarios. When the user is connected to the domain and signs in after a reset, Active Directory automatically validates the new password and prompts for a change if required; cached logon data is refreshed automatically during successful authentication. Forcing a cache clear can disrupt the user's local profile and encrypted data, and it does not address the root cause of the password lockout or reset request.

  • ✗

    Update the user's Security Identifier (SID) in Active Directory

    Why it's wrong here

    Updating a user's Security Identifier (SID) in Active Directory is neither possible nor relevant after a password reset, as the SID is a unique, immutable object identifier used by Windows for ACLs, group memberships, and security principal lookups. Password changes only alter the password hash in the directory database; they do not regenerate or require any modification of the SID. Attempting to delete and recreate the user to change the SID would destroy group memberships and permissions, making it a harmful and incorrect action in this scenario.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.