SY0-701 Security Program Management and Oversight Practice Question
A help desk technician receives a ticket asking for a password reset on a manager's account. The requester says the manager is traveling and cannot be reached. What is the best action before making any change?
⚠ Common exam trap
Many exam-takers assume urgency (Option A) is acceptable, but CompTIA emphasizes that security controls must never be bypassed for convenience, and password sharing (Option C) is always a violation of security best practices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify the request through an approved identity-check process before taking action.
The principle of least privilege and proper identity verification are critical before performing any privileged action like a password reset. Without verifying the requester's identity through an approved process (e.g., out-of-band verification, knowledge-based authentication, or manager callback), the technician risks unauthorized access, which could lead to a security breach. This aligns with the CompTIA SY0-701 objective on implementing identity and access management controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reset the password immediately to avoid delaying the manager's work.
Why it's wrong here
Resetting the password immediately to avoid delaying the manager's work bypasses all identity verification and authorization steps, which is exactly what social engineering exploits. An attacker who merely claims to be a manager and creates a sense of urgency could gain control of a legitimate account without any proof. Security policies require identity proofing via out-of-band verification, and privileges like password resets must not be granted based on perceived time pressure. This action also violates the principle of least privilege and change management, potentially leading to a data breach.
- ✓
Verify the request through an approved identity-check process before taking action.
Why this is correct
The best action is to verify the requester and the request using the organization's approved process before changing access. This helps prevent social engineering and unauthorized account changes. Account resets are sensitive because they can give an attacker control if the help desk relies only on a convincing story or urgent pressure.
- ✗
Tell the requester to ask a coworker to share the manager's existing password.
Why it's wrong here
Telling the requester to have a coworker share the manager's existing password directly violates password policies and destroys non-repudiation, as multiple individuals would then know the secret. This practice makes it impossible to attribute actions taken under that account to the actual account owner and increases the attack surface by distributing credentials. Additionally, the coworker has no authority to share another person's password, and the requester might not even be a legitimate employee. The correct procedure is to issue a temporary credential through an approved identity-check process, not to reuse or expose an existing one.
- ✗
Ignore the ticket until the manager returns from travel.
Why it's wrong here
Ignoring the ticket until the manager returns from travel is not a security control because it does nothing to verify the requester's identity or the request's legitimacy; it simply delays the decision. An attacker could just as easily disrupt the manager's work by resubmitting the request later, and a legitimate request would be unnecessarily blocked, causing business disruption. Proper security requires an approved verification process, such as a call back to the manager on a known phone number or confirmation through a second authorized party, rather than assuming that waiting inherently mitigates risk. This approach mistakenly equates inactivity with protection, leaving unresolved vulnerabilities.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Access token
A digital key that a computer system gives you to prove your identity and grant you permission to access specific resources or perform actions.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.