easyMultiple Choice
220-1102 Practice Question: A technician receives a call from someone…
A technician receives a call from someone claiming to be from the company's IT security team, asking for the administrator password to 'run a critical update.' The caller's voice sounds stressed and they mention a data breach. What should the technician do?
⚠ Common exam trap
This question tests the candidate's ability to resist urgency and authority-based social engineering by presenting a scenario where the caller seems legitimate and the threat appears imminent, leading candidates to prioritize speed over verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ask for a callback number and verify it against the company directory.
It follows the principle of verifying identity through a trusted channel before disclosing sensitive information. The technician should ask for a callback number and cross-reference it against the company directory to ensure the caller is legitimate, as social engineering attacks often use urgency and impersonation to bypass security protocols.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Provide the password immediately to prevent a data breach.
Why it's wrong here
Supplying the password lets an unverified caller take administrative control, since urgency and claimed breaches are standard social-engineering pressure tactics. Providing credentials is only defensible after identity is confirmed through an independent, trusted channel — never on the caller's word.
- ✓
Ask for a callback number and verify it against the company directory.
Why this is correct
Verifying the caller independently through the company directory defeats pretexting and vishing, since a genuine IT security team member can be confirmed through official channels. Never disclose the administrator password based on an unverified inbound call.
- ✗
Ignore the call because IT never calls about updates.
Why it's wrong here
Ignoring the call discards the chance to verify and report a suspected vishing attempt through proper channels. IT does legitimately contact staff about updates, so refusing all such calls would block genuine support; the correct action is verifying identity via a known number.
- ✗
Change the password and give them the new one.
Why it's wrong here
Changing the password and disclosing it hands credentials to an unverified caller, defeating the control entirely and locking out legitimate administrators. Password rotation is a valid response to a confirmed compromise, not to an unsolicited request during an unverified call.
Go deeper
Related to this question
Learn chapter
Data Sanitization: Wipe, Degauss, Shred, Incinerate
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.