220-1102 Operational Procedures Practice Question
A help desk technician is creating a standard operating procedure (SOP) for handling password reset requests. Which of the following components is MOST important to include in the SOP to ensure consistency and security?
⚠ Common exam trap
The trap here is that candidates often focus on procedural completeness (logging, ticket numbers) or presentation (email templates) rather than the critical security gate of identity verification, which is the primary control against unauthorized password changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A step-by-step method to verify the identity of the user before resetting the password
The most important component for consistency and security in a password reset SOP is a step-by-step method to verify the user's identity before resetting the password. Without proper identity verification, an attacker could social-engineer a password reset and gain unauthorized access, violating the principle of least privilege and potentially leading to a data breach. This step ensures that only authorized users can request a password change, which is a critical security control in operational procedures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A list of acceptable password reset email templates
Why it's wrong here
Standardized email templates for password reset notifications only serve as user communication after the reset has been executed. They do not contribute to verifying the requester's identity or preventing an unauthorized actor from initiating a reset. While they aid in consistent messaging, they are a convenience feature, not a security control, and thus are not the most critical element of the SOP.
- ✓
A step-by-step method to verify the identity of the user before resetting the password
Why this is correct
A step-by-step identity verification method is the most critical component because it directly addresses the primary threat of social engineering. By systematically confirming the requester's identity—through knowledge-based questions, multi-factor authentication, or supervisor approval—the procedure ensures that only legitimate account owners can trigger a password reset. Without this control, any attacker who tricks the help desk could hijack an account, making all other steps subordinate to this security gate.
- ✗
The format for the help desk ticket number
Why it's wrong here
The help desk ticket number format is an administrative convention that simply provides a unique reference for tracking individual requests. It has no bearing on the security of the password reset process, as it neither authenticates the user nor authorizes the action. Even a poorly structured ticket number would not increase the risk of unauthorized resets, making it a procedural triviality rather than a critical element.
- ✗
Instructions for logging the password reset in the ticketing system after completion
Why it's wrong here
Logging the password reset in the ticketing system is a post-event audit activity that documents what occurred, but it occurs after the reset has already been granted. This logging cannot intercept or stop an unauthorized reset in progress, because by the time the log entry is created, the potential damage—such as account compromise—has already been done. While auditing is important for accountability and incident investigation, it is a reactive measure, not the proactive control that identity verification provides.
Go deeper
Related to this question
Learn chapter
Browser Security Settings and Add-ons
Key term
Standard Operating Procedure
A Standard Operating Procedure is a detailed, written set of step-by-step instructions that describes how to perform a specific task or process consistently and safely.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.