Courseiva
easyMultiple ChoiceObjective-mapped

220-1202 Practice Question: A technician receives a complaint from a user…

A technician receives a complaint from a user that their email account was used to send spam. The user insists they did not send the emails. What is the MOST appropriate first step in handling this security incident professionally?

⚠ Common exam trap

CompTIA often tests the candidate's ability to prioritize containment over investigation or blame; the trap here is that many candidates jump to blaming the user (Option A) or taking a passive approach (Option D), when the correct first step is to immediately secure the account by resetting the password.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Immediately reset the user's password and check the email logs for unauthorized access.

The immediate reset of the user's password stops further unauthorized use of the account, and checking email logs (e.g., SMTP logs, IMAP/POP3 access logs, or Exchange/Office 365 audit logs) allows the technician to identify the source of the spam, such as a compromised credential or a malicious forwarding rule. This follows the CompTIA A+ incident response procedure of containment first, then investigation, while maintaining professional communication with the user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Tell the user they must have clicked on a phishing link and it's their fault.

    Why it's wrong here

    This approach is unprofessional and counterproductive. Attributing blame without conducting a thorough investigation into the incident's root cause not only alienates the user but also risks overlooking the actual security vulnerability. A technician's role is to diagnose and resolve issues, not to prematurely assign fault, especially when the compromise could stem from various sources beyond user error, such as a system vulnerability or a sophisticated attack.

  • Immediately reset the user's password and check the email logs for unauthorized access.

    Why this is correct

    This is the most appropriate immediate response to a potential account compromise. Resetting the password severs any active unauthorized sessions and prevents further malicious activity from the compromised account, thereby securing it. Concurrently, examining email logs provides critical forensic evidence to identify the source, scope, and timeline of the unauthorized access, which is essential for understanding the attack vector and implementing broader preventative measures.

  • Ignore the complaint because spam is common.

    Why it's wrong here

    Ignoring a user's complaint about potential account compromise, even if it seems like common spam, is a severe dereliction of duty and a significant security risk. Such an oversight could allow an attacker to maintain persistent access, escalate privileges, or launch further attacks from the compromised account, leading to broader organizational data breaches or system compromise. All security complaints warrant investigation, regardless of initial perceived severity.

  • Ask the user to change their password and not worry about it.

    Why it's wrong here

    While instructing the user to change their password is a necessary step in securing a compromised account, it is insufficient on its own. Simply changing the password without investigating the underlying cause, such as a phishing attack, malware infection, or a broader system breach, leaves the user and the organization vulnerable to future attacks. A comprehensive response requires understanding how the compromise occurred to prevent recurrence and ensure no other accounts or systems are affected.

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.