Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A technician detects that an attacker has gained unauthorized access to a file server using a stolen user account. The technician can see active connections from the attacker in the server logs. According to incident response best practices, which action should the technician take FIRST?

⚠ Common exam trap

Test-takers frequently confuse the order of incident response phases (identification, containment, eradication, recovery) and prioritize forensic collection (memory dump) or notification over the immediate containment step required to stop active attacker connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable the compromised user account

Disabling the compromised user account is the immediate containment action to stop the attacker's active access, aligning with the 'containment' phase of incident response. The technician has confirmed active connections via server logs, so cutting off authentication prevents further data exfiltration or lateral movement without waiting for additional personnel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Take a memory dump of the server

    Why it's wrong here

    A memory dump is a forensic preservation step, not a containment step. While capturing volatile memory may preserve evidence of the attacker's in-memory artifacts (e.g., injected code, cached credentials), it does not stop the attacker from continuing to act or from destroying other evidence. In incident response, the priority is to contain the threat first—disabling the account or isolating the host—and only then perform memory capture to support investigation and legal proceedings.

  • ✗

    Notify the system administrator

    Why it's wrong here

    Notifying the system administrator is an important communication step, but it is a reactionary action that does not directly impede the attacker's active session. Unless the administrator is immediately able to perform a containment action, the attacker retains access and can continue moving laterally or exfiltrating data. Proper incident response protocols place containment (such as disabling the account or isolating the host) before escalation notifications, so the notification alone is insufficient as the first response.

  • ✓

    Disable the compromised user account

    Why this is correct

    Disabling the compromised user account is the most effective immediate containment step because it invalidates the account's ability to authenticate and, in most directory services (e.g., Active Directory), forces the termination of existing Kerberos ticket-granting tickets (TGTs) and can revoke active sessions depending on enforcement. This directly severs the attacker's current access path and prevents new logons using those credentials. It is a reversible and low-impact action that keeps the system available for forensic investigation while neutralizing the immediate threat.

  • ✗

    Change the password on the compromised account

    Why it's wrong here

    Changing the password on the account only affects future authentication attempts; it does not automatically invalidate already issued access tokens, Kerberos TGTs, or NTLM cached credentials. Many protocols, especially Kerberos, rely on ticket lifetimes and session keys that remain valid until expiration even after a password reset. An attacker with an active session can continue using the existing ticket or token, so disabling the account—which blocks all authentication and forces session revocation—is the more reliable containment measure.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A technician discovers an unknown user account with administrative privileges on a Windows 10 workstation during a routine security audit. The account was created two days ago, but no one in the IT department authorized its creation. According to incident response best practices, what should the technician do FIRST?

medium
  • A.Delete the account immediately to remove the threat.
  • ✓ B.Disable the account and gather evidence such as logs and system images.
  • C.Change the account password and monitor its activity.
  • D.Ignore it because it might be a legitimate test account created by another technician.

Why B: Incident response best practices prioritize containment and preservation of evidence over immediate eradication. Disabling the account prevents further unauthorized access while allowing the technician to collect forensic data (e.g., security event logs, registry hives, and system images) to determine the attack vector and scope of compromise. Deleting the account immediately (Option A) would destroy critical evidence needed for root cause analysis and potential legal proceedings.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.