Courseiva
easyMultiple Choice

220-1202 Practice Question: A technician receives a call from someone…

A technician receives a call from someone claiming to be from the company's IT security team, asking for the administrator password to 'run a critical update.' The caller's voice sounds stressed and they mention a data breach. What should the technician do?

⚠ Common exam trap

This question tests the candidate's ability to resist urgency and authority-based social engineering by presenting a scenario where the caller seems legitimate and the threat appears imminent, leading candidates to prioritize speed over verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ask for a callback number and verify it against the company directory.

It follows the principle of verifying identity through a trusted channel before disclosing sensitive information. The technician should ask for a callback number and cross-reference it against the company directory to ensure the caller is legitimate, as social engineering attacks often use urgency and impersonation to bypass security protocols.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Provide the password immediately to prevent a data breach.

    Why it's wrong here

    Supplying the password lets an unverified caller take administrative control, since urgency and claimed breaches are standard social-engineering pressure tactics. Providing credentials is only defensible after identity is confirmed through an independent, trusted channel — never on the caller's word.

  • ✓

    Ask for a callback number and verify it against the company directory.

    Why this is correct

    Verifying the caller independently through the company directory defeats pretexting and vishing, since a genuine IT security team member can be confirmed through official channels. Never disclose the administrator password based on an unverified inbound call.

  • ✗

    Ignore the call because IT never calls about updates.

    Why it's wrong here

    Ignoring the call discards the chance to verify and report a suspected vishing attempt through proper channels. IT does legitimately contact staff about updates, so refusing all such calls would block genuine support; the correct action is verifying identity via a known number.

  • ✗

    Change the password and give them the new one.

    Why it's wrong here

    Changing the password and disclosing it hands credentials to an unverified caller, defeating the control entirely and locking out legitimate administrators. Password rotation is a valid response to a confirmed compromise, not to an unsolicited request during an unverified call.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.