Courseiva
hardMultiple ChoiceObjective-mapped

220-1102 Practice Question: A technician is investigating a security incident…

A technician is investigating a security incident where a user's corporate email account was accessed from an unknown device. The user's iPhone shows no suspicious apps, and the password was recently changed. Which of the following is the MOST likely cause?

⚠ Common exam trap

CompTIA often tests the distinction between password-based attacks and token-based persistence, where candidates mistakenly assume that changing the password immediately revokes all access, ignoring OAuth tokens or app-specific passwords that remain valid.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

An OAuth token or app-specific password was stolen and used to access the account.

OAuth tokens or app-specific passwords bypass the need for the primary password, allowing persistent access even after a password change. Since the user's iPhone shows no suspicious apps and the password was recently changed, a stolen token is the most plausible vector for unauthorized email access via Exchange ActiveSync or modern authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The user's iCloud account was compromised, and the email is synced via Exchange.

    Why it's wrong here

    A compromise of the user's iCloud account would primarily impact services tied directly to Apple's ecosystem, such as iCloud Mail, Photos, or backups. Corporate email accessed via Exchange typically relies on distinct organizational credentials and authentication protocols (e.g., Active Directory, multi-factor authentication) managed by the company, not Apple. Therefore, a breach of iCloud would not inherently grant unauthorized access to the corporate Exchange mailbox.

  • An OAuth token or app-specific password was stolen and used to access the account.

    Why this is correct

    OAuth tokens and app-specific passwords provide delegated access to an account without exposing the user's primary password. Once stolen or maliciously generated, these credentials can grant persistent, unauthorized access to specific services, like email, even if the main account password is subsequently changed. This mechanism allows an attacker to bypass traditional password authentication and maintain access, aligning with a scenario where suspicious activity continues despite password resets.

  • The user's iPhone has a jailbreak that hides malicious apps.

    Why it's wrong here

    While a jailbroken iPhone could potentially hide malicious applications, the question implies that no suspicious apps were found during the investigation. Furthermore, even if a hidden app were present, its primary function would typically be data exfiltration or device control, not necessarily persistent, direct access to an email account via a server-side mechanism like Exchange without a password. This scenario is less probable than a stolen credential providing direct email access.

  • The corporate email server has a backdoor account.

    Why it's wrong here

    A backdoor account on the corporate email server would indeed grant unauthorized access, but this represents a server-side compromise affecting all users or specific targets, rather than a client-side vulnerability related to a single user's mobile device or account delegation. While possible, it's a broader infrastructure issue and typically less common for isolated incidents of persistent access to a single user's email than the compromise of a specific user's delegated access credential.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.