220-1102 Security Practice Question
A technician discovers an unknown user account with administrative privileges on a Windows 10 workstation during a routine security audit. The account was created two days ago, but no one in the IT department authorized its creation. According to incident response best practices, what should the technician do FIRST?
⚠ Common exam trap
It's easy for candidates to confuse immediate threat removal (deletion) with proper incident response, failing to recognize that evidence preservation is the first priority in a structured response plan.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the account and gather evidence such as logs and system images.
Incident response best practices prioritize containment and preservation of evidence over immediate eradication. Disabling the account prevents further unauthorized access while allowing the technician to collect forensic data (e.g., security event logs, registry hives, and system images) to determine the attack vector and scope of compromise. Deleting the account immediately (Option A) would destroy critical evidence needed for root cause analysis and potential legal proceedings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the account immediately to remove the threat.
Why it's wrong here
Immediately deleting the account is destructive and shortsighted. It removes the SID and all associated event log entries, which could be the only evidence for how the attacker gained persistence. It also fails to prevent the attacker from using other backdoors or creating new accounts, so the threat may persist while the investigation is blind.
- ✓
Disable the account and gather evidence such as logs and system images.
Why this is correct
Disabling the account blocks further sign-ins while leaving the account object, its SID, and its properties intact for forensic examination. Capture system logs, such as event ID 4720/4738 (account creation/change), a memory dump, and disk images before altering any other settings. This supports a root cause analysis and maintains the chain of custody for potential legal action.
- ✗
Change the account password and monitor its activity.
Why it's wrong here
Changing the account password only invalidates the known credential, but sophisticated attackers often maintain other persistence mechanisms like services, scheduled tasks, or registry run keys. Monitoring alone is a passive action that allows continued lateral movement if the attacker is still on the network. Additionally, altering the password modifies a forensic artifact (the password hash) and could alert the adversary that they are being investigated.
- ✗
Ignore it because it might be a legitimate test account created by another technician.
Why it's wrong here
Ignoring the account on the assumption that another technician created it is a dangerous denial of the principle of least privilege. Legitimate test accounts are typically documented and approved through change management; the correct action is to verify with the team, not assume. Without verification, an attacker's persistence mechanism can remain undetected and active, allowing data exfiltration or further compromise.
Go deeper
Related to this question
Learn chapter
Data Classification Levels
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.