220-1102 Security Practice Question
A company policy requires that all printed documents containing sensitive customer data must be collected immediately from the printer. A technician observes that an employee printed a report containing customer Personally Identifiable Information (PII) and left it in the printer tray for over an hour. Which security principle has been violated?
⚠ Common exam trap
A common mix-up: candidates confuse improper data handling with social engineering or shoulder surfing, but the key distinction is that the violation is a procedural failure to secure printed data, not an active attack or deception technique.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Improper data handling
The employee violated the security principle of improper data handling by printing a document containing PII and leaving it unattended in the printer tray for over an hour. This directly contravenes the company policy requiring immediate collection of printed sensitive documents, exposing customer data to unauthorized access. Proper data handling mandates that sensitive information be secured at all times, including during the printing process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Shoulder surfing
Why it's wrong here
Shoulder surfing is a direct observation attack where an attacker visually captures sensitive information such as passwords, PINs, or on-screen data by looking over the victim's shoulder or using optical devices. It requires the victim to be actively viewing or entering information, not the simple failure to retrieve printed documents from a shared printer. The scenario describes a physical omission after printing, not an active act of visual eavesdropping, so this option does not match the breach.
- ✗
Dumpster diving
Why it's wrong here
Dumpster diving is a post-disposal attack in which an adversary sifts through trash, recycle bins, or dumpsters to recover discarded hard copies, storage media, or other sensitive materials. In this incident, the issue is the failure to pick up the printed documents immediately, leaving them exposed on the printer's output tray, not the later recovery of items that have already been thrown away. Because the attacker would not need to enter a dumpster to find these prints, the action does not correspond to dumpster diving.
- ✗
Social engineering
Why it's wrong here
Social engineering is an attack vector that exploits human psychology and trust to manipulate individuals into divulging confidential information or performing actions, such as by impersonating a colleague or sending a phishing email. It does not describe the physical aftermath of printing, where sensitive customer PII sits unsecured at the printer awaiting retrieval. The security lapse here is an inanimate object left in a public space, not a psychological manipulation performed on a person.
- ✓
Improper data handling
Why this is correct
Improper data handling occurs when sensitive information is processed or stored in a manner that does not comply with organizational security policies, including the physical control of printed output. Leaving customer PII unattended at a shared printer is a clear violation of data-handling procedures that require immediate retrieval, secure storage, and possibly the use of secure print-release features. This is the only option that directly matches a failure in the lifecycle of the data—from the printer output to final storage—and therefore is the correct classification.
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
Personally identifiable information
Personally identifiable information (PII) is any data that can be used to identify, contact, or locate a specific individual, either alone or when combined with other information.
Key term
PII
PII stands for Personally Identifiable Information, which is any data that can be used to identify a specific individual.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.