220-1102 Operational Procedures Practice Question
A help desk technician receives a call from a user who reports that they received an email asking them to click a link and enter their corporate credentials to 'verify their account.' The user clicked the link and entered their username and password. According to incident response best practices, what should the technician do FIRST?
⚠ Common exam trap
Many candidates assume the immediate, intuitive action (changing the password) is correct, but the CompTIA 220-1102 exam emphasizes following the incident response plan and escalating to the security team first, not taking unilateral action that could compromise the investigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate the incident to the security team according to the incident response plan
The user has already compromised their credentials by entering them into a phishing site. According to incident response best practices, the first step is to escalate the incident to the security team as defined in the incident response plan, so that the scope of the breach can be assessed, affected accounts can be identified, and coordinated remediation (including password resets and account lockdowns) can be performed systematically. Changing the password immediately without escalation could interfere with forensic analysis or miss broader lateral movement by an attacker.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the user's password immediately
Why it's wrong here
Immediately changing the password might be necessary to invalidate a known compromise, but doing so without following the incident response plan omits critical notifications, approval, and documentation. The security team must first triage the report to identify indicators of compromise and ensure that no other accounts share the same credentials or exposure before any change is made. Additionally, an uncoordinated change can lock out the legitimate user during an investigation and disrupt business operations.
- ✓
Escalate the incident to the security team according to the incident response plan
Why this is correct
Escalating to the security team according to the incident response plan is the correct first action because it initiates the formal process for handling a potential breach. The security team has the expertise and tooling to investigate the scope, detect lateral movement, and decide on containment actions while preserving evidence. This also ensures proper communication, chain of custody, and compliance with organizational policy, which are essential before any remediation is attempted.
- ✗
Disable the user's account to prevent further access
Why it's wrong here
Disabling the user's account proactively may temporarily stop unauthorized access, but as an uncoordinated containment action it can tip off the attacker and prevent the security team from observing ongoing malicious activity. The security team needs the opportunity to conduct active monitoring and forensic collection to understand how the account was compromised and what other resources may be affected. Only after escalation and proper authorization should account disabling be executed as part of a broader containment strategy.
- ✗
Reset the user's password to a temporary value
Why it's wrong here
Resetting the user's password to a temporary value is a remediation step that should not be performed before escalating the incident. Without authorization from the security team, a premature reset can destroy session-related evidence, interfere with forensic analysis, and fail to address the underlying compromise vector. Proper incident response requires preserving forensic data and determining the scope of the breach before altering credentials.
Go deeper
Related to this question
Learn chapter
IT Policies: AUP, BYOD, Password Policy
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A help desk technician receives a call from a panicked user who reports that they accidentally shared a confidential client list with an unauthorized person via email. According to the company's incident response plan, what should the technician do FIRST?
medium- A.Attempt to recall the email from the user's email client
- B.Delete the email from the user's sent items to reduce visibility
- C.Contact the recipient directly and ask them to delete the email
- ✓ D.Escalate the incident according to the company's incident response policy
Why D: The company's incident response plan dictates the first step in any security incident is to follow the established escalation procedure. This ensures proper documentation, containment, and legal compliance, rather than taking ad-hoc actions that could destroy evidence or violate policy. The technician must not attempt to tamper with the data or contact the unauthorized recipient directly, as that could compromise the investigation.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.