hardMultiple ChoiceObjective-mapped
220-1102 Practice Question: A technician is investigating a security incident…
A technician is investigating a security incident where a user's corporate email account was accessed from an unknown device. The user's iPhone shows no suspicious apps, and the password was recently changed. Which of the following is the MOST likely cause?
⚠ Common exam trap
CompTIA often tests the distinction between password-based attacks and token-based persistence, where candidates mistakenly assume that changing the password immediately revokes all access, ignoring OAuth tokens or app-specific passwords that remain valid.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An OAuth token or app-specific password was stolen and used to access the account.
OAuth tokens or app-specific passwords bypass the need for the primary password, allowing persistent access even after a password change. Since the user's iPhone shows no suspicious apps and the password was recently changed, a stolen token is the most plausible vector for unauthorized email access via Exchange ActiveSync or modern authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user's iCloud account was compromised, and the email is synced via Exchange.
Why it's wrong here
A compromise of the user's iCloud account would primarily impact services tied directly to Apple's ecosystem, such as iCloud Mail, Photos, or backups. Corporate email accessed via Exchange typically relies on distinct organizational credentials and authentication protocols (e.g., Active Directory, multi-factor authentication) managed by the company, not Apple. Therefore, a breach of iCloud would not inherently grant unauthorized access to the corporate Exchange mailbox.
- ✓
An OAuth token or app-specific password was stolen and used to access the account.
Why this is correct
OAuth tokens and app-specific passwords provide delegated access to an account without exposing the user's primary password. Once stolen or maliciously generated, these credentials can grant persistent, unauthorized access to specific services, like email, even if the main account password is subsequently changed. This mechanism allows an attacker to bypass traditional password authentication and maintain access, aligning with a scenario where suspicious activity continues despite password resets.
- ✗
The user's iPhone has a jailbreak that hides malicious apps.
Why it's wrong here
While a jailbroken iPhone could potentially hide malicious applications, the question implies that no suspicious apps were found during the investigation. Furthermore, even if a hidden app were present, its primary function would typically be data exfiltration or device control, not necessarily persistent, direct access to an email account via a server-side mechanism like Exchange without a password. This scenario is less probable than a stolen credential providing direct email access.
- ✗
The corporate email server has a backdoor account.
Why it's wrong here
A backdoor account on the corporate email server would indeed grant unauthorized access, but this represents a server-side compromise affecting all users or specific targets, rather than a client-side vulnerability related to a single user's mobile device or account delegation. While possible, it's a broader infrastructure issue and typically less common for isolated incidents of persistent access to a single user's email than the compromise of a specific user's delegated access credential.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.