Courseiva
Operational Procedures →easyMultiple Choice

220-1102 Operational Procedures Practice Question

A help desk technician needs to create a document that specifies the exact steps to follow when resetting a user's password, including verification of identity. Which type of document should be created?

⚠ Common exam trap

Many exam-takers confuse 'policy' (the 'why') with 'procedure' (the 'how'), because both are mandatory, but only a procedure specifies the exact step-by-step actions required for a task like password reset.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Procedure

A procedure is the correct type of document because it provides a detailed, step-by-step sequence of actions to achieve a specific outcome—in this case, resetting a user's password with identity verification. Procedures are mandatory and prescriptive, ensuring consistency and security in operational tasks. Policies define high-level rules, standards set technical benchmarks, and guidelines offer flexible recommendations, none of which match the exact-step requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Policy

    Why it's wrong here

    A policy is a high-level statement of management intent, such as 'all password resets must be verified with the user's manager.' While it sets rules and expectations, it does not describe the concrete actions to perform the reset, such as navigating to Active Directory or using a specific tool. Policies provide the 'why' and governance framework, not the 'how-to' steps needed for a technician to execute a task reliably.

  • ✓

    Procedure

    Why this is correct

    A procedure is the correct choice because it specifies the exact, ordered steps to perform a task, such as resetting a user's password in a help desk environment. Procedures eliminate guesswork and enforce consistency by requiring every technician to follow the same sequence of actions. They are typically written as standard operating procedures (SOPs) and include specifics like which commands to run, which fields to update, and how to verify success.

  • ✗

    Standard

    Why it's wrong here

    A standard defines mandatory technical requirements or configuration baselines, such as requiring passwords to be at least 12 characters with complexity. It specifies the end state or minimum acceptable configuration, but not the process to achieve it. Thus, a standard for password complexity would not tell a technician how to perform a reset; it only dictates what the resulting password must satisfy.

  • ✗

    Guideline

    Why it's wrong here

    A guideline is a recommended practice or best practice that offers flexibility, such as 'it is often helpful to verify the user's identity via a secondary method.' Guidelines are not mandatory and intentionally allow discretion, which can lead to inconsistent execution. For a password reset process that must be identical every time, a guideline is too vague because it does not prescribe the exact commands, screens, or verification steps.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.