220-1102 Operational Procedures Practice Question
A technician notices a user has written their password on a sticky note attached to the edge of their monitor. According to IT security best practices, what should the technician do first?
⚠ Common exam trap
A common mix-up: candidates assume the technician should immediately fix the problem themselves (by removing the note or resetting the password) rather than following the formal escalation chain required by IT security best practices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the violation to the appropriate supervisor or security team
The correct first step is to report the violation to the appropriate supervisor or security team because IT security best practices require that policy violations be escalated through proper channels to ensure documentation, investigation, and consistent enforcement. The technician should not take corrective action themselves, as that could destroy evidence or bypass formal incident response procedures. This aligns with the principle of separation of duties and the need for a clear audit trail in security incident handling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Report the violation to the appropriate supervisor or security team
Why this is correct
Reporting the violation to the appropriate supervisor or security team is the correct action because it follows the organization's incident response and reporting policy. It ensures that the security team can properly document the incident, preserve evidence (such as the sticky note), and determine the appropriate remediation steps, which may include a password reset or further investigation. A technician should not take independent corrective action because doing so can destroy evidence, bypass established procedures, and potentially expose the organization to additional risk.
- ✗
Remove the sticky note and remind the user not to post passwords
Why it's wrong here
Removing the sticky note and reminding the user not to post passwords is an incorrect response because it is an unauthorized corrective action that bypasses the organization's incident reporting chain. This approach destroys potential evidence of a policy violation before the security team can assess the scope of the exposure (e.g., who may have seen the password). It also fails to ensure that the incident is formally documented, which is required for compliance and for identifying broader security awareness training needs.
- ✗
Reset the user's password and issue a temporary password
Why it's wrong here
Resetting the user's password and issuing a temporary password without authorization is a violation of change-management and incident-handling policies. This action could disrupt the user's work, lock them out of necessary systems, and conflict with the official remediation process, which requires the security team to first assess the breach and coordinate a controlled reset. It also fails to preserve forensic evidence and does not address the underlying problem of unsafe password storage.
- ✗
Ignore the sticky note as it is a minor policy violation
Why it's wrong here
Ignoring the sticky note as a minor policy violation is dangerous because any exposure of credentials, regardless of perceived severity, can lead to unauthorized access or a data breach. Password hygiene policies exist precisely to prevent such oversights, and even a seemingly small violation should be reported so that the organization can track patterns, mitigate risks, and reinforce security awareness. Ignoring it also signals that policy enforcement is lax, encouraging further unsafe behaviors.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Separation of duties
Separation of duties is a security principle that splits critical tasks and privileges among multiple people to prevent fraud, errors, and abuse of power.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.