Courseiva
hardMultiple Choice

220-1202 Practice Question: A technician receives an email from what appears…

A technician receives an email from what appears to be the company's CEO, asking for a list of all employee passwords for a 'security audit'. The email address is correct, but the tone and request are unusual. The technician suspects a social engineering attack. What is the best course of action?

⚠ Common exam trap

CompTIA often tests the misconception that verifying with the CEO by phone is the best immediate action, but the correct priority is to report to the security team first to ensure proper incident response and evidence preservation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Forward the email to the security team and do not respond.

Forwarding the email to the security team ensures that the incident is handled by the appropriate personnel who can investigate the potential phishing or social engineering attack without engaging the attacker. Responding to the email, even for confirmation, could validate the technician's email address as active and potentially expose the organization to further attacks. The security team can analyze headers, links, and attachments using tools like email security gateways or SIEM systems to determine the legitimacy of the request.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reply to the email asking for more details to confirm the request.

    Why it's wrong here

    Replying to the sender immediately confirms that your mailbox is actively monitored, a signal attackers use to target you with more sophisticated spear-phishing or pretexting. It also gives the attacker a foothold to escalate the social engineering attempt and undermines the proper incident response workflow. Any verification must be performed through a separate, out-of-band channel such as a phone call to a known number, never by replying to the suspect email.

  • ✓

    Forward the email to the security team and do not respond.

    Why this is correct

    This is the correct response because forwarding the suspicious message to the security team preserves the original headers and metadata, enabling forensic analysis of sender authentication (SPF, DKIM, DMARC) and malicious indicators like phishing links or attached payloads. It also establishes a written record for incident response timelines and ensures no action is taken that could enable credential theft or data exposure. Do not click any links, open attachments, or reply before security triage.

  • ✗

    Provide the list as requested, since the CEO has authority.

    Why it's wrong here

    Providing the password list would constitute a severe data exposure regardless of the sender's apparent authority, because the email could be spoofed via look-alike domain or display-name forgery. Password lists are never shared or transmitted through email; doing so violates the principle of least privilege, acceptable use policies, and potentially regulatory compliance requirements. This action would give an attacker valid corporate credentials and almost certainly trigger a full-scale breach notification.

  • ✗

    Call the CEO immediately to verify the request.

    Why it's wrong here

    While verifying by phone is a good general practice, in this situation the technician's first responsibility is to alert the security team, who can conduct a controlled investigation and determine whether the CEO was actually compromised or the email is part of a broader campaign. Directly calling the CEO risks interfering with that investigation—for example, if the CEO is the attacker's impersonation target, the call could unintentionally reveal details about the incident. The security team can then coordinate verification through established incident response channels without jeopardizing forensic evidence.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.