Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A help desk technician receives a call from a user who reports that they received an email asking them to click a link and enter their corporate credentials to 'verify their account.' The user clicked the link and entered their username and password. According to incident response best practices, what should the technician do FIRST?

⚠ Common exam trap

Many candidates assume the immediate, intuitive action (changing the password) is correct, but the CompTIA 220-1102 exam emphasizes following the incident response plan and escalating to the security team first, not taking unilateral action that could compromise the investigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Escalate the incident to the security team according to the incident response plan

The user has already compromised their credentials by entering them into a phishing site. According to incident response best practices, the first step is to escalate the incident to the security team as defined in the incident response plan, so that the scope of the breach can be assessed, affected accounts can be identified, and coordinated remediation (including password resets and account lockdowns) can be performed systematically. Changing the password immediately without escalation could interfere with forensic analysis or miss broader lateral movement by an attacker.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the user's password immediately

    Why it's wrong here

    Immediately changing the password might be necessary to invalidate a known compromise, but doing so without following the incident response plan omits critical notifications, approval, and documentation. The security team must first triage the report to identify indicators of compromise and ensure that no other accounts share the same credentials or exposure before any change is made. Additionally, an uncoordinated change can lock out the legitimate user during an investigation and disrupt business operations.

  • ✓

    Escalate the incident to the security team according to the incident response plan

    Why this is correct

    Escalating to the security team according to the incident response plan is the correct first action because it initiates the formal process for handling a potential breach. The security team has the expertise and tooling to investigate the scope, detect lateral movement, and decide on containment actions while preserving evidence. This also ensures proper communication, chain of custody, and compliance with organizational policy, which are essential before any remediation is attempted.

  • ✗

    Disable the user's account to prevent further access

    Why it's wrong here

    Disabling the user's account proactively may temporarily stop unauthorized access, but as an uncoordinated containment action it can tip off the attacker and prevent the security team from observing ongoing malicious activity. The security team needs the opportunity to conduct active monitoring and forensic collection to understand how the account was compromised and what other resources may be affected. Only after escalation and proper authorization should account disabling be executed as part of a broader containment strategy.

  • ✗

    Reset the user's password to a temporary value

    Why it's wrong here

    Resetting the user's password to a temporary value is a remediation step that should not be performed before escalating the incident. Without authorization from the security team, a premature reset can destroy session-related evidence, interfere with forensic analysis, and fail to address the underlying compromise vector. Proper incident response requires preserving forensic data and determining the scope of the breach before altering credentials.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A help desk technician receives a call from a panicked user who reports that they accidentally shared a confidential client list with an unauthorized person via email. According to the company's incident response plan, what should the technician do FIRST?

medium
  • A.Attempt to recall the email from the user's email client
  • B.Delete the email from the user's sent items to reduce visibility
  • C.Contact the recipient directly and ask them to delete the email
  • ✓ D.Escalate the incident according to the company's incident response policy

Why D: The company's incident response plan dictates the first step in any security incident is to follow the established escalation procedure. This ensures proper documentation, containment, and legal compliance, rather than taking ad-hoc actions that could destroy evidence or violate policy. The technician must not attempt to tamper with the data or contact the unauthorized recipient directly, as that could compromise the investigation.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.