nerdexam
Cisco

100-140 · Question #10

A user who has been on vacation for the past 30 days calls the help desk and reaches you. The user reports the following: Before I left for vacation, I changed my password and made sure it worked…

The correct answer is A. Tell the user to install the company's authenticator app. C. Tell the user to add a phone number to their account for SMS validation. A user cannot log in after a new MFA policy was enforced company-wide during their absence. The solution requires enrolling the user in MFA via one of the supported second-factor methods.

Basic Security Concepts

Question

A user who has been on vacation for the past 30 days calls the help desk and reaches you. The user reports the following: Before I left for vacation, I changed my password and made sure it worked. My password is not due to be reset for another 60 days, but I can't log in to the network. While the user was gone, the company established a requirement for Multi-Factor Authentication (MFA). Which two actions could you take to resolve the problem? (Choose two.) Note: Each correct answer presents a complete solution.

Options

  • ATell the user to install the company's authenticator app.
  • BSet the user's password to never expire.
  • CTell the user to add a phone number to their account for SMS validation.
  • DTell the user to change their password to one that meets complexity requirements.
  • EUnlock the user's account.

How the community answered

(26 responses)
  • A
    77% (20)
  • B
    12% (3)
  • D
    8% (2)
  • E
    4% (1)

Why each option

A user cannot log in after a new MFA policy was enforced company-wide during their absence. The solution requires enrolling the user in MFA via one of the supported second-factor methods.

ATell the user to install the company's authenticator app.Correct

Installing the company authenticator app is a valid MFA enrollment method. Since MFA was made mandatory while the user was away, they were never enrolled, so providing an authenticator app (TOTP-based) satisfies the new second-factor requirement and restores login access.

BSet the user's password to never expire.

Setting the password to never expire does not address the MFA enrollment gap that is preventing login; password expiry is unrelated to the reported problem.

CTell the user to add a phone number to their account for SMS validation.Correct

Adding a phone number for SMS validation is an alternative MFA enrollment method. SMS-based one-time passcodes serve as a valid second factor, meaning this also fully resolves the login failure caused by the missing MFA enrollment.

DTell the user to change their password to one that meets complexity requirements.

The user already has a valid, unexpired password, so changing it to meet complexity requirements does not resolve an MFA enforcement block.

EUnlock the user's account.

There is no indication the account is locked; the problem is that MFA was never configured for the user, not that the account exceeded failed-login attempts.

Concept tested: Multi-Factor Authentication enrollment and troubleshooting

Source: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mfa-howitworks

Topics

#MFA#authenticator app#SMS validation#account access

Community Discussion

No community discussion yet for this question.

Full 100-140 Practice