A help desk team is writing a procedure for resetting MFA after a user loses a phone. Which two details belong in the procedure rather than in the policy? Select two.
The exact step-by-step verification process is the core of any standard operating procedure. For MFA resets, this includes verifying the user's identity via a secondary channel (e.g., manager approval, knowledge-based verification) and enumerating the sequence of admin console actions. This specificity ensures that any technician performs the reset identically, minimizing risk of unauthorized changes and creating an auditable trail.
Why this answer
A procedure must contain the exact step-by-step verification process the technician follows to confirm the user's identity before resetting MFA. This operational detail ensures consistency and security, whereas a policy would only state the high-level requirement (e.g., 'verify identity'). Without precise steps, technicians might skip critical checks, leading to unauthorized MFA resets.
Exam trap
The trap here is confusing policy (broad rules and goals) with procedure (specific, actionable steps), leading candidates to select high-level statements like 'all employees must use MFA' instead of the detailed verification and tool-specific steps that actually belong in a procedure.