hardMultiple ChoiceObjective-mapped
220-1102 Practice Question: A technician is deploying a new point-of-sale…
A technician is deploying a new point-of-sale system in a busy retail store. The store manager insists on a specific configuration that the technician knows will cause data security vulnerabilities. Which of the following is the BEST course of action?
⚠ Common exam trap
CompTIA often tests the trap that candidates choose Option A (compliance with authority) or Option B (rigid refusal) instead of the balanced, professional approach of explaining risks and proposing alternatives, which is the core of CompTIA's 'Communication and Professionalism' domain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Explain the security risks in non-technical terms and propose a secure alternative that meets their needs.
It aligns with the CompTIA A+ objective of balancing security with business needs. The technician must communicate the security risks of the manager's requested configuration (e.g., using default credentials or disabling encryption on the POS system) in non-technical terms, then propose a secure alternative that still meets the operational requirements, such as using WPA3 with a strong passphrase instead of an open Wi-Fi network. This approach maintains professionalism, avoids data breaches, and preserves the working relationship.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement the configuration as requested to keep the manager happy.
Why it's wrong here
Implementing a configuration that violates established security best practices, even if requested by a manager, directly exposes the Point-of-Sale (POS) system to significant vulnerabilities. This could lead to unauthorized access to sensitive customer payment data, potential data breaches, and severe financial and reputational damage for the business. A technician's professional obligation includes safeguarding system integrity and data security, not just fulfilling requests blindly.
- ✗
Refuse to do the work and walk away.
Why it's wrong here
Simply refusing to perform the work and walking away is highly unprofessional and fails to address the underlying security concern or the client's operational needs. This approach abandons the client, leaves the security vulnerability unmitigated, and does not provide an opportunity to educate or offer a secure alternative. A responsible technician seeks to resolve issues, not create new ones through non-communication or abandonment.
- ✓
Explain the security risks in non-technical terms and propose a secure alternative that meets their needs.
Why this is correct
This is the most professional and effective approach, demonstrating a technician's commitment to both client satisfaction and robust security. By translating complex technical risks into understandable language, the technician empowers the manager to make informed decisions regarding their system's security posture. Proposing a secure alternative ensures the system's operational requirements are met while mitigating potential vulnerabilities, thereby protecting sensitive data and the business's reputation.
- ✗
Secretly implement a secure configuration and tell the manager it's what they asked for.
Why it's wrong here
Secretly implementing a different configuration than requested, even if more secure, and then misrepresenting it to the manager is a severe breach of professional ethics and honesty. This deceptive practice erodes trust, can lead to future operational misunderstandings or compliance issues, and fundamentally undermines the technician's credibility. Transparency and open communication are paramount in maintaining professional client relationships and ensuring long-term system integrity.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
PSK
A pre-shared key (PSK) is a secret string of characters shared in advance between two parties to authenticate and encrypt wireless or VPN communications.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.