220-1102 Operational Procedures Practice Question
After resetting a user's forgotten password, what is the most appropriate next step for a help desk technician?
⚠ Common exam trap
Many candidates assume documenting the password in the ticket is helpful for future reference, but CompTIA emphasizes security policies that forbid storing passwords in plaintext, making option C a clear violation of operational procedures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the user can log in successfully with the new password
After resetting a user's password, the help desk technician must verify that the user can log in successfully with the new password. This ensures the password change was properly applied in Active Directory or the local SAM database, and that the user can authenticate without errors such as 'account locked' or 'password must change at next logon' flags. Skipping verification risks unresolved authentication issues, leading to a repeat ticket and user frustration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Close the help desk ticket
Why it's wrong here
Closing the help desk ticket before the user confirms the password reset actually works is premature and violates standard incident management practice. A ticket should only be marked resolved after the user verifies they can complete the intended task, otherwise unresolved access issues may linger unaddressed after closure. Once closed without confirmation, the user may face a logon failure and would need to reopen a new ticket, causing delay and metric distortion.
- ✓
Verify that the user can log in successfully with the new password
Why this is correct
Verifying successful logon with the new password is the definitive proof that the password change was applied correctly across the authentication infrastructure, whether it is a local account, Active Directory domain, or identity provider. This end-to-end test confirms the user's account is not disabled, locked out, or subject to a requiring change at next logon policy that would block access. It also prevents the technician from assuming the reset worked merely because the password was changed server-side, which is the only reliable closure criterion.
- ✗
Document the new password in the ticket for future reference
Why it's wrong here
Recording the new password in plain text within the ticket is a severe security violation because help desk tickets are often visible to multiple technicians, auditors, and potentially in archived logs or forwarded emails. If the ticket database is compromised, the plaintext credential grants direct access to the user's account, and because the password is now known to more than one person, accountability for any subsequent misuse is destroyed. The correct practice is to provide the temporary password through a secure channel, require the user to change it at first login, and never store credentials in ticketing systems.
- ✗
Escalate the ticket to a senior technician
Why it's wrong here
Escalating a routine password reset to a senior technician is an unnecessary deviation from standard operating procedure because password resets fall squarely within the help desk's delegated identity-management authority. Senior technicians have more valuable focus for complex incidents such as systemic authentication failures or security policy modifications, and escalation would only add delay for the user waiting to regain access. Escalation is warranted only if the reset fails because the account is locked, the user does not have permission to reset the target account, or underlying authentication infrastructure is suspected to be faulty.
Visual reference
Go deeper
Related to this question
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.