Courseiva
hardMultiple ChoiceObjective-mapped

220-1102 Practice Question: A technician is responding to a security incident…

A technician is responding to a security incident where an employee's credentials were used to access a server without authorization. The employee claims they did not perform the action. Which of the following should the technician do first to remediate the compromised account?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disable the account to prevent further access.

The immediate step is to disable the compromised account to prevent further unauthorized access. Then the technician should force a password reset and enable multi-factor authentication (MFA) to secure the account. Logging and investigation follow containment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Reset the account password and enable MFA.

    Why it's wrong here

    While resetting the password and enabling Multi-Factor Authentication (MFA) are crucial remediation steps, they should not be the immediate first action during an active security incident. An attacker might still be actively logged in or have established persistent access through other means, rendering a password reset alone ineffective at immediately stopping ongoing unauthorized activity. The priority is to sever all current connections and prevent any further actions by the compromised account before attempting to re-secure it.

  • Disable the account to prevent further access.

    Why this is correct

    Disabling the compromised account is the paramount first step in incident response, specifically within the containment phase. This action immediately revokes all authentication tokens and active sessions associated with the account, effectively severing the attacker's current access and preventing any further unauthorized actions or data exfiltration. It provides a critical window for the security team to investigate and remediate the breach without the attacker continuing to operate within the system.

  • Review the server logs to determine the extent of the breach.

    Why it's wrong here

    Reviewing server logs is an essential part of the investigation phase of incident response, providing crucial forensic data to understand the scope, timeline, and methods of the breach. However, it is not the initial containment action. Prioritizing log review over disabling the compromised account would allow the attacker to potentially continue their malicious activities, causing further damage or data loss while the technician is still gathering information. Containment must precede extensive investigation.

  • Notify the employee's manager and HR department.

    Why it's wrong here

    Notifying the employee's manager and the Human Resources department is a vital communication and procedural step within the incident response framework, ensuring proper organizational awareness and potential personnel actions. However, this administrative notification should follow the immediate technical containment of the threat. The primary objective in the initial moments of a security incident is to technically neutralize the ongoing unauthorized access before engaging in broader communication protocols, which could otherwise delay critical technical actions.

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.