Courseiva
Operational Procedures →easyMultiple Choice

220-1102 Operational Procedures Practice Question

A technician finds an unknown USB flash drive in the company parking lot. The drive is labeled 'Confidential Q4 Results'. According to operational procedures, what should the technician do?

⚠ Common exam trap

Test-takers frequently think a 'test machine' is safe because it's isolated, but the CompTIA 220-1102 exam emphasizes that any unknown media must be handled by security professionals to avoid zero-day exploits or firmware-level attacks that can bypass isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Turn the drive over to the IT security team for proper handling.

Operational security procedures require that any unknown storage media found on company premises be immediately turned over to the IT security team. This prevents potential malware infections, data breaches, or introduction of malicious code into the corporate network, as USB drives can be weaponized with autorun.inf scripts or BadUSB attacks that emulate a keyboard to execute commands.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Plug the drive into a test machine to check its contents.

    Why it's wrong here

    Connecting an unknown USB drive to any workstation, even a designated test machine, is dangerous because many devices feature autorun or HID firmware that executes a payload before the OS can inspect the files. In addition, a test machine often shares network resources or has a different security profile, so malware could still spread to the broader environment. Without forensic tools and an isolated network, this action risks a breach and violates incident-response best practices.

  • ✓

    Turn the drive over to the IT security team for proper handling.

    Why this is correct

    The correct response is to maintain chain of custody by sealing the drive in an evidence bag and reporting it to the IT security team, who will image it for forensic analysis in a hardened, isolated environment. This allows the team to safely determine whether the device contains malicious code, sensitive data, or any clues pointing to its owner. Proper handling also ensures any incident is documented and investigated according to organizational policy, rather than being uncontrolled.

  • ✗

    Format the drive and reuse it for company data.

    Why it's wrong here

    Reformatting an unknown USB drive does not eliminate threats nested in the device's firmware or hidden partitions, such as a BadUSB payload that persists after a standard rewrite. Moreover, the drive may contain proprietary or personal data that belongs to another employee, customer, or subject—reusing it without authorization could result in unlawful handling of that information and violate data privacy regulations. The drive must be formally controlled and assessed before any reuse is even considered.

  • ✗

    Dispose of the drive in a regular trash bin.

    Why it's wrong here

    Throwing the drive into a regular trash bin abandons all control over the data it may hold, since standard flash storage retains recoverable bits even after attempts at deletion. Improper disposal is exactly how confidential passwords, patient records, or business secrets end up in the hands of dumpster divers and forensic attackers. NIST and security frameworks mandate media sanitization via erasure or physical destruction, so this method fails both security and compliance requirements.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.