220-1102 Operational Procedures Practice Question
A technician is called to a user's desk where the user has left a sticky note with their password taped to the monitor. The technician needs to document this in the ticket. Which of the following should the technician do FIRST?
⚠ Common exam trap
The trap here is assuming the technician should immediately remove the note or handle it informally, rather than following the formal incident reporting procedure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the security violation according to the organization's incident response policy.
The correct action is to report the security violation according to policy. Passwords left in plain sight are a serious security risk that must be escalated through proper channels. This allows the organization to handle the situation consistently, educate the user, and prevent similar incidents. Taking direct action like removing the note or sharing it could interfere with investigations or violate privacy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Report the security violation according to the organization's incident response policy.
Why this is correct
Leaving a password visible is a security violation that must be reported through the proper incident response channel. This ensures the organization can investigate, educate the user, and enforce policies. Documenting and reporting is the first step before taking any corrective action that might destroy evidence or overstep the technician's authority.
- ✗
Ignore it because it is the user's personal workspace and not the technician's concern.
Why it's wrong here
Ignoring a visible password violates the technician's duty to protect organizational assets. Security is everyone's responsibility, and operational procedures require reporting such incidents. The technician's scope of support includes maintaining a secure environment, so this is definitely a concern.
- ✗
Remove the sticky note and discard it, then close the ticket as resolved.
Why it's wrong here
Removing the note destroys evidence of a policy violation and does not address the underlying security risk. Closing the ticket as resolved without educating the user or reporting the incident fails to meet operational procedures for handling sensitive information. The technician should not alter the scene before documenting and reporting.
- ✗
Take a photo of the sticky note and post it in the team chat as a joke.
Why it's wrong here
Sharing a photo of a password, even as a joke, further exposes credentials and violates the user's privacy and the organization's security policies. This action could lead to disciplinary action against the technician and does not follow proper incident handling. It also fails to address the security risk appropriately.
Go deeper
Related to this question
Learn chapter
Browser Security Settings and Add-ons
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Privacy
Privacy in IT is the control over how personal data is collected, stored, used, and shared by systems and organizations.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.