Courseiva
hardMultiple ChoiceObjective-mapped

220-1102 Practice Question: A technician is helping a user who accidentally…

A technician is helping a user who accidentally installed a potentially unwanted program (PUP) that changed their browser homepage and search engine. The user is embarrassed and asks the technician not to tell their manager. What is the most ethical response?

⚠ Common exam trap

CompTIA often tests the distinction between a 'security incident' (e.g., malware with C2 traffic) and a 'policy violation' (e.g., PUP installation), tempting candidates to overreact with option C or underreact with option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Explain that you will remove the PUP but must document the incident per company policy, though you will not share unnecessary details.

It balances the user's privacy concern with the technician's professional obligation to follow company policy. Documenting the incident (e.g., in a help desk ticket) is standard procedure for tracking PUP infections, which may indicate broader security issues like drive-by downloads or social engineering. The technician can remove the PUP using tools like Malwarebytes or AdwCleaner while omitting the user's name from unnecessary reports, preserving trust without violating policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Agree not to tell the manager and remove the PUP quietly.

    Why it's wrong here

    This action directly violates professional ethics and company security policies, which typically mandate documentation and reporting of any unauthorized software installation or potential security incident, even if seemingly minor like a PUP. Failing to report could lead to a lack of awareness regarding common user mistakes, potential widespread infection, or non-compliance with regulatory requirements, undermining the organization's overall security posture.

  • Explain that you will remove the PUP but must document the incident per company policy, though you will not share unnecessary details.

    Why this is correct

    This approach demonstrates both empathy for the user's honest mistake and adherence to professional IT protocols. Documenting the incident, even for a Potentially Unwanted Program (PUP), is crucial for tracking potential vulnerabilities, identifying training needs, and maintaining an accurate security log, which is often a compliance requirement. Reassuring the user that unnecessary details will not be shared helps maintain trust while fulfilling technical and policy obligations.

  • Tell the user that this is a serious security breach and you have to report it immediately.

    Why it's wrong here

    Labeling a PUP installation as a "serious security breach" is an overreaction that can cause undue alarm and erode user trust. While PUPs do pose risks and require removal and documentation, they are generally less severe than active malware infections or data breaches. Exaggerating the threat level can create an environment of fear, making users less likely to report future issues honestly.

  • Ignore the request and report the user to HR for violating IT policy.

    Why it's wrong here

    Immediately escalating to HR for an accidental PUP installation is an overly punitive and unconstructive response. This approach fails to address the technical issue at hand and assumes malicious intent, which is rarely the case with PUPs. A technician's role includes educating users and resolving technical problems, not solely acting as an enforcer, and such harshness can foster user resentment and reluctance to seek IT assistance.

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.