220-1102 Operational Procedures Practice Question
A help desk technician receives a call from a user who states they clicked on a link in an email that appeared to be from the company's CEO requesting urgent action. The user entered their username and password on the resulting webpage. Which of the following is the FIRST step the technician should take according to incident response procedures?
⚠ Common exam trap
Many exam-takers choose 'Run an antivirus scan' first, mistakenly thinking the link delivered malware, when the core issue is credential theft requiring immediate access revocation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reset the user's password and revoke tokens
The user's credentials have been compromised via a phishing attack. The immediate priority is to prevent unauthorized access by invalidating the current password and any active authentication tokens, such as session cookies or OAuth refresh tokens. This aligns with the 'containment' phase of incident response, stopping the attacker from using the stolen credentials before any further damage occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify the user's manager
Why it's wrong here
While managerial notification is part of incident escalation, it is not an immediate containment action. The account remains compromised while you communicate; the attacker could continue using the harvested credentials to access email, cloud apps, or internal resources. Proper incident response order is to contain the threat first (e.g., disable account, reset password, revoke sessions) and then notify stakeholders like the manager with accurate information about the containment steps taken.
- ✓
Reset the user's password and revoke tokens
Why this is correct
Because the user's credentials have been harvested, the attacker may have already established active sessions or obtained OAuth tokens that remain valid even after a password change. Immediately resetting the password invalidates the known credential, and revoking tokens/sessions (e.g., via Microsoft Entra ID sign-out everywhere, Google account session revocation, or forcing a password reset that ends sessions) terminates the attacker's existing access. This is a containment action that directly addresses the confirmed compromise vector.
- ✗
Run an antivirus scan
Why it's wrong here
An antivirus scan is a detection/eradication step that addresses a potential malware infection on the user's machine, but it does nothing to invalidate the already-harvested credentials. Even if no malware is found, the attacker can still use the stolen password or tokens from any remote location. The first response to a known credential compromise is to deny access through account reset and token revocation; malware scanning may be part of later root cause analysis but is not the immediate priority.
- ✗
Block the CEO's email address
Why it's wrong here
Blocking the CEO's email address in the spam filter would only filter messages from that one spoofed or compromised sender, but the attacker has already harvested the user's credentials and can send from the user's own account or use other phishing infrastructure. This action does not affect the attacker's ability to authenticate as the victim, access data, or send emails from the compromised mailbox. The correct containment action is to revoke the compromised account's credentials and sessions, not to add a block rule based on a sender address.
Go deeper
Related to this question
Learn chapter
IT Policies: AUP, BYOD, Password Policy
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.