Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A help desk technician receives a call from a panicked user who reports that they accidentally shared a confidential client list with an unauthorized person via email. According to the company's incident response plan, what should the technician do FIRST?

⚠ Common exam trap

Many candidates assume a technical fix (recall or delete) is the fastest way to mitigate the breach, but CompTIA emphasizes following the incident response policy first to ensure proper handling and evidence preservation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Escalate the incident according to the company's incident response policy

The company's incident response plan dictates the first step in any security incident is to follow the established escalation procedure. This ensures proper documentation, containment, and legal compliance, rather than taking ad-hoc actions that could destroy evidence or violate policy. The technician must not attempt to tamper with the data or contact the unauthorized recipient directly, as that could compromise the investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attempt to recall the email from the user's email client

    Why it's wrong here

    Attempting to recall the email is an Exchange/Outlook client feature that sends a recall request to the recipient's mailbox, but it is unreliable across domains and does not guarantee deletion, especially if the recipient has already read the message or if the email is on an unmanaged device. More importantly, initiating a recall before notifying the incident response team can alter or destroy forensic evidence, such as message headers, routing logs, and mailbox copies, which are needed to determine the scope and cause of the incident. The recall action should only be considered after the appropriate team has been engaged and has approved this containment step.

  • ✗

    Delete the email from the user's sent items to reduce visibility

    Why it's wrong here

    Deleting the email from the sender's sent items only removes the local copy in the user's mailbox; it does not remove, recall, or quarantine the email from the recipient's mailbox, the mail server's transport logs, or any journaling/archiving system. This action also degrades critical evidence, as the sent item is often a key artifact for forensic analysis, showing the exact content, recipients, and timestamp. Moreover, deleting the sent item may be viewed as an unauthorized tampering with data, which could violate legal hold or evidence-preservation obligations, making the technician's action counterproductive to the investigation.

  • ✗

    Contact the recipient directly and ask them to delete the email

    Why it's wrong here

    Contacting the recipient directly without coordination with the incident response team is risky because the recipient may react emotionally, forward the email to others, or delete it, which can further spread the data and destroy evidence. The technician also lacks the authority and context to determine whether the incident is a data breach, a misdelivered sensitive message, or a security violation, so any external communication could trigger procedural or legal problems. Direct outreach should be left to the incident response team, which can follow proper notification protocols, preserve a chain of custody, and issue legally compliant messaging if recipient contact is warranted.

  • ✓

    Escalate the incident according to the company's incident response policy

    Why this is correct

    Escalating the incident according to the company's incident response policy is the correct first action because it triggers the formal process of notification, analysis, containment, and evidence preservation. A help desk technician is not equipped to assess the full scope or severity of a possible data exfiltration or accidental disclosure, and taking unilateral actions like recall or deletion can destroy forensic data. Escalation to a designated incident response team or manager ensures that trained personnel can implement appropriate hold measures, coordinate with legal/compliance, and determine the proper escalation path, which protects the organization from further harm and regulatory penalties.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.