Courseiva
Operational Procedures →easyMultiple Choice

220-1102 Operational Procedures Practice Question

A technician is called to a user's desk where the user has left a sticky note with their password taped to the monitor. The technician needs to document this in the ticket. Which of the following should the technician do FIRST?

⚠ Common exam trap

The trap here is assuming the technician should immediately remove the note or handle it informally, rather than following the formal incident reporting procedure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Report the security violation according to the organization's incident response policy.

The correct action is to report the security violation according to policy. Passwords left in plain sight are a serious security risk that must be escalated through proper channels. This allows the organization to handle the situation consistently, educate the user, and prevent similar incidents. Taking direct action like removing the note or sharing it could interfere with investigations or violate privacy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Report the security violation according to the organization's incident response policy.

    Why this is correct

    Leaving a password visible is a security violation that must be reported through the proper incident response channel. This ensures the organization can investigate, educate the user, and enforce policies. Documenting and reporting is the first step before taking any corrective action that might destroy evidence or overstep the technician's authority.

  • ✗

    Ignore it because it is the user's personal workspace and not the technician's concern.

    Why it's wrong here

    Ignoring a visible password violates the technician's duty to protect organizational assets. Security is everyone's responsibility, and operational procedures require reporting such incidents. The technician's scope of support includes maintaining a secure environment, so this is definitely a concern.

  • ✗

    Remove the sticky note and discard it, then close the ticket as resolved.

    Why it's wrong here

    Removing the note destroys evidence of a policy violation and does not address the underlying security risk. Closing the ticket as resolved without educating the user or reporting the incident fails to meet operational procedures for handling sensitive information. The technician should not alter the scene before documenting and reporting.

  • ✗

    Take a photo of the sticky note and post it in the team chat as a joke.

    Why it's wrong here

    Sharing a photo of a password, even as a joke, further exposes credentials and violates the user's privacy and the organization's security policies. This action could lead to disciplinary action against the technician and does not follow proper incident handling. It also fails to address the security risk appropriately.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.