Courseiva
mediumMultiple ChoiceObjective-mapped

220-1202 Practice Question: During a software deployment, a user reports that…

During a software deployment, a user reports that a stranger in a delivery uniform asked to use their computer to 'check a shipment status' and then quickly left. Later, the user notices unusual network activity. What should the technician investigate first?

⚠ Common exam trap

The CompTIA A+ exam often tests the candidate's ability to prioritize immediate technical containment over administrative or non-technical follow-ups; the trap here is that many candidates choose Option B (verifying identity) because it seems logical for a physical security breach, but the exam expects you to recognize that the workstation is already compromised and must be investigated first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Scan the workstation for malware and review recent system changes.

The scenario describes a classic social engineering attack where an unauthorized individual gains physical access to a workstation under a pretext. The immediate technical priority is to scan the workstation for malware and review recent system changes because the attacker may have installed a backdoor, keylogger, or remote access trojan (RAT) that explains the unusual network activity. This aligns with incident response best practices: isolate and analyze the affected system first to contain potential data exfiltration or lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Check the user's email for phishing messages.

    Why it's wrong here

    While email phishing is a common attack vector, the reported incident specifically involves unauthorized physical access to a workstation. Focusing on email at this stage diveres resources from investigating the direct, physical compromise, which presents a more immediate and different threat vector than a remote email-based attack. The priority is to address the known physical breach first.

  • Verify the delivery person's identity with the shipping company.

    Why it's wrong here

    Verifying the delivery person's identity, while a valid step for post-incident analysis or evidence gathering, is not the immediate priority for containing the potential compromise. The primary concern after unauthorized physical access is to assess and mitigate any immediate threats to the system's integrity and data, rather than focusing solely on the perpetrator's identity or external administrative tasks.

  • Scan the workstation for malware and review recent system changes.

    Why this is correct

    Unauthorized physical access to a workstation creates a high probability that an attacker could have installed malicious software, altered system configurations, or created backdoors for future access. Scanning for malware identifies immediate threats, while reviewing recent system changes helps pinpoint unauthorized modifications, making these crucial first steps in containment, eradication, and investigation to restore system integrity.

  • Disable the user's network access permanently.

    Why it's wrong here

    Permanently disabling a user's network access is an extreme measure that could hinder the incident response process and is disproportionate to the initial report. The user may be a victim, and their access might be necessary for investigation, evidence collection, or to understand the scope of the compromise without prematurely assuming malicious intent on their part. Temporary isolation might be considered, but not permanent disablement.

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.