Courseiva
Operational Procedures →easyMultiple Choice

220-1102 Operational Procedures Practice Question

A help desk technician is creating a standard operating procedure (SOP) for handling password reset requests. Which of the following components is MOST important to include in the SOP to ensure consistency and security?

⚠ Common exam trap

The trap here is that candidates often focus on procedural completeness (logging, ticket numbers) or presentation (email templates) rather than the critical security gate of identity verification, which is the primary control against unauthorized password changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A step-by-step method to verify the identity of the user before resetting the password

The most important component for consistency and security in a password reset SOP is a step-by-step method to verify the user's identity before resetting the password. Without proper identity verification, an attacker could social-engineer a password reset and gain unauthorized access, violating the principle of least privilege and potentially leading to a data breach. This step ensures that only authorized users can request a password change, which is a critical security control in operational procedures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A list of acceptable password reset email templates

    Why it's wrong here

    Standardized email templates for password reset notifications only serve as user communication after the reset has been executed. They do not contribute to verifying the requester's identity or preventing an unauthorized actor from initiating a reset. While they aid in consistent messaging, they are a convenience feature, not a security control, and thus are not the most critical element of the SOP.

  • ✓

    A step-by-step method to verify the identity of the user before resetting the password

    Why this is correct

    A step-by-step identity verification method is the most critical component because it directly addresses the primary threat of social engineering. By systematically confirming the requester's identity—through knowledge-based questions, multi-factor authentication, or supervisor approval—the procedure ensures that only legitimate account owners can trigger a password reset. Without this control, any attacker who tricks the help desk could hijack an account, making all other steps subordinate to this security gate.

  • ✗

    The format for the help desk ticket number

    Why it's wrong here

    The help desk ticket number format is an administrative convention that simply provides a unique reference for tracking individual requests. It has no bearing on the security of the password reset process, as it neither authenticates the user nor authorizes the action. Even a poorly structured ticket number would not increase the risk of unauthorized resets, making it a procedural triviality rather than a critical element.

  • ✗

    Instructions for logging the password reset in the ticketing system after completion

    Why it's wrong here

    Logging the password reset in the ticketing system is a post-event audit activity that documents what occurred, but it occurs after the reset has already been granted. This logging cannot intercept or stop an unauthorized reset in progress, because by the time the log entry is created, the potential damage—such as account compromise—has already been done. While auditing is important for accountability and incident investigation, it is a reactive measure, not the proactive control that identity verification provides.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.