220-1102 Operating Systems Practice Question
A technician is configuring a new Windows 10 workstation for a user who travels frequently. The user needs to be able to log in without an internet connection. The workstation is joined to Microsoft Entra ID. Which sign-in option should the technician configure to provide offline access?
⚠ Common exam trap
Many exam-takers assume passwordless methods like Microsoft Authenticator work offline, but they require network connectivity for the challenge-response or notification, whereas the PIN is hardware-bound and cached locally.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Hello PIN
The Windows Hello PIN is stored locally on the device using the TPM (Trusted Platform Module) and is validated against a locally cached credential, allowing the user to sign in without an internet connection. This makes it ideal for a traveling user with an Microsoft Entra ID-joined workstation who needs offline access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Windows Hello PIN
Why this is correct
The Windows Hello PIN is a device-bound credential, not a shared password: the PIN itself is never stored on any server, and it unlocks an asymmetric key pair that is sealed by the Trusted Platform Module (TPM) inside the workstation. On a Microsoft Entra ID (Azure AD) joined device, this key and the associated user identity are cached locally, so the user can sign in and access the desktop even with no network connectivity or VPN. Because the PIN is tied to the specific device and protected by the TPM, it also resists credential theft—it cannot be used on another machine—and is the recommended sign-in method for traveling users who need offline access to a corporate workstation.
- ✗
Passwordless sign-in with Microsoft Authenticator
Why it's wrong here
Passwordless sign-in with the Microsoft Authenticator app is a cloud-based authentication flow: the user attempts to sign in, the workstation contacts the Entra ID authentication service, a push notification is sent to the user's registered phone, and the user must tap approve (or enter a number match) before the service issues an authentication token. This entire exchange requires the phone to have an active internet connection and the workstation to reach the cloud service; if either is offline—as can happen on a plane or in a remote location—the sign-in cannot complete. Unlike the Windows Hello PIN, no cached credential is stored locally for this method, so it fails the requirement of logging into an Entra ID-joined workstation without network connectivity.
- ✗
Picture Password
Why it's wrong here
Picture Password is a Windows 8/10 feature that allows sign-in by drawing gestures on a picture. It works offline but is less secure and not typically recommended for corporate devices. It is also not the standard for Microsoft Entra ID.
- ✗
Physical Security Key (FIDO2)
Why it's wrong here
A FIDO2 security key requires a USB or NFC connection and cryptographic challenge-response with the local device, but it does not cache Microsoft Entra ID credentials for offline sign-in; the user must have internet access to complete the initial authentication against the cloud. It is tempting because FIDO2 provides strong passwordless authentication and works offline for local device unlock, but it cannot satisfy the stem’s requirement of logging into a Microsoft Entra ID-joined workstation without network connectivity—only a cached PIN or biometric (Windows Hello for Business) stores credentials locally for that purpose.
Go deeper
Related to this question
Learn chapter
Windows Device Manager
Key term
Trusted Platform Module
A Trusted Platform Module (TPM) is a dedicated microcontroller chip that securely stores cryptographic keys, passwords, and certificates to protect a computer's hardware and ensure system integrity.
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.