Courseiva
hardMultiple Choice

220-1202 Practice Question: A security analyst discovers that an attacker has…

A security analyst discovers that an attacker has been using a compromised VPN account to access the corporate network. The account belongs to a former employee who was terminated two weeks ago. Which of the following should the analyst do immediately to prevent further unauthorized access?

⚠ Common exam trap

A common mix-up: candidates choose to review logs first (Option A) to understand the breach, but the correct priority is immediate containment over forensic analysis in an active security incident.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable the former employee's VPN account

Disabling the former employee's VPN account immediately stops the attacker from using the compromised credentials to access the corporate network. This is the most direct and effective action to prevent further unauthorized access, as the account is the vector being exploited. Other steps like log review or server reconfiguration are important but secondary to cutting off the active attack path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Review the VPN logs to determine the extent of the breach

    Why it's wrong here

    Log review is forensic, not containment; the attacker keeps using the live VPN account throughout. It is tempting because scoping the breach is a genuine later step, and reviewing logs would be correct once access is revoked and evidence preserved.

  • ✓

    Disable the former employee's VPN account

    Why this is correct

    Disabling the account immediately revokes authentication, terminating the attacker's active VPN session and blocking reconnection. Since the former employee was terminated two weeks ago, the account should already have been deprovisioned; disabling satisfies the stem's requirement to prevent further unauthorised access without disrupting other users.

  • ✗

    Change the VPN server's shared secret

    Why it's wrong here

    The shared secret authenticates the VPN tunnel between peers, not individual users, so rotating it does not stop a compromised user account. It is tempting because shared secrets are credentials, and rotation is correct when a tunnel key or pre-shared secret itself leaks.

  • ✗

    Notify the former employee about the security incident

    Why it's wrong here

    Notifying the former employee alerts a possible threat actor and does nothing to revoke the compromised VPN account. Notification would be correct only where the individual is a current trusted party who must be told of an incident affecting their credentials.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.