Courseiva
Operational Procedures →easyMultiple Choice

220-1102 Operational Procedures Practice Question

A junior technician discovers what appears to be a data breach involving sensitive customer information on a network server. According to standard incident response procedures, what is the FIRST step the technician should take?

⚠ Common exam trap

Watch out — candidates often confuse 'immediate containment' with 'immediate shutdown,' but proper incident response prioritizes evidence preservation and notification over hasty actions that destroy forensic data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Notify the incident response team or the appropriate manager as defined in the company policy

The first step in any standard incident response procedure is to notify the incident response team or the appropriate manager as defined in the company policy. This ensures that the incident is properly documented, escalation paths are followed, and actions are coordinated to preserve evidence and minimize damage. Shutting down the server or running scans prematurely can destroy volatile data (e.g., memory contents, active network connections) and compromise forensic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately shut down the affected server to prevent further data loss

    Why it's wrong here

    Immediately powering off the server is a hasty containment action that destroys volatile evidence such as RAM contents, active network connections, and running processes — data that is essential for forensic analysis. It also risks corrupting logs and may be interpreted as a failure to follow the incident response plan. In incident response, preservation of evidence takes priority over ad-hoc shutdowns; the correct first move is always to escalate per company policy.

  • ✓

    Notify the incident response team or the appropriate manager as defined in the company policy

    Why this is correct

    Notifying the incident response team or the appropriate manager as defined in company policy is the mandatory first step because it activates the documented incident response plan. This ensures that trained personnel take charge of evidence preservation, chain of custody, and legal/regulatory notifications, and it prevents the junior technician from making unilateral decisions that could compromise the investigation. Reporting first is consistent with the CompTIA A+ incident response procedures and the organization's escalation path.

  • ✗

    Run a full antivirus and antimalware scan on the affected server

    Why it's wrong here

    Running a full antivirus and antimalware scan is an investigation and remediation activity that belongs after the incident is reported and containment is planned. Performing the scan prematurely can alter file timestamps, quarantine suspicious artifacts, or trigger malicious code, thereby destroying evidence and compromising the forensic timeline. Additionally, antivirus tools are not a substitute for proper incident response; they cannot capture memory dumps or fully analyze a stealthy attacker’s behavior.

  • ✗

    Change all user passwords on the network

    Why it's wrong here

    Changing all user passwords is a disruptive containment measure that should not be executed as a first response. It may lock out legitimate users, alert the attacker to detection, and prevent the incident response team from observing and analyzing compromised accounts and lateral movement. Password resets must be coordinated and approved by the appropriate authority after the incident is reported and the scope is assessed — doing it immediately violates proper escalation procedure.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.