mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: A helpdesk technician receives a call from an…
A helpdesk technician receives a call from an employee who says their smart card stopped working for building access. The employee is in a hurry and asks the technician to remotely disable the card and issue a temporary PIN for the day. What should the technician do first?
⚠ Common exam trap
Test-takers frequently assume the helpdesk has full control over all credential types (logical and physical) and can perform remote operations on smart cards, when in fact physical access systems are usually separate and require in-person identity verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ask the employee to visit the security office in person with a photo ID.
Smart card credentials for physical access are typically managed by a separate physical security system (e.g., an access control server), not the helpdesk's IT identity management system. The technician cannot remotely disable the card or issue a temporary PIN without proper authorization and verification of the caller's identity. The standard procedure is to require in-person verification with a photo ID at the security office to prevent social engineering attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the smart card and provide a temporary PIN as requested.
Why it's wrong here
Acting without verification could grant access to an imposter.
- ✓
Ask the employee to visit the security office in person with a photo ID.
Why this is correct
In-person verification with a photo ID ensures the request is legitimate before making changes.
- ✗
Reset the smart card remotely and test it with a badge reader.
Why it's wrong here
Resetting without verification still risks unauthorized access.
- ✗
Send a temporary PIN via email to the employee's company address.
Why it's wrong here
Email can be intercepted; also, identity is not confirmed.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.