hardMultiple Choice
220-1102 Practice Question: A technician receives an email that appears to be…
A technician receives an email that appears to be from the company's HR department asking them to click a link to update their direct deposit information. The email contains several grammatical errors and the sender's domain is 'company-hr.com' instead of the official 'company.com'. What is the most effective way to confirm this is a phishing attempt?
⚠ Common exam trap
CompTIA A+ exams often test the principle that verifying suspicious emails through official channels (e.g., security team) is safer than any direct interaction with the email's contents or contacts, and the trap here is that candidates may think calling a listed number is safe, but attackers can spoof phone numbers or use VoIP to appear legitimate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Forward the email to the company's security team for analysis.
Forwarding the suspicious email to the company's security team allows trained analysts to inspect headers, attachments, and URLs in a sandboxed environment without exposing the technician to risk. This aligns with organizational incident response procedures for phishing, as the security team can verify the sender domain (e.g., SPF/DKIM/DMARC failures) and determine if the email is malicious.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reply to the email asking for verification.
Why it's wrong here
Replying confirms the address is live and reaches the attacker, who will simply reassure the technician. The sender domain 'company-hr.com' already fails verification against the official 'company.com'. Replying suits routine internal queries, but never validates a suspicious external sender's identity.
- ✗
Click the link to see if it looks legitimate.
Why it's wrong here
Clicking the link risks credential theft or malware execution and cannot confirm sender authenticity, since phishing pages are designed to look genuine. Clicking is only safe in isolated sandbox environments used for malware analysis, never on a production workstation.
- ✓
Forward the email to the company's security team for analysis.
Why this is correct
Forwarding the suspicious email to the security team lets trained analysts examine headers, links and sender infrastructure, confirming the phishing attempt without the technician interacting with malicious content. This satisfies the need for authoritative verification rather than relying on visible red flags alone.
- ✗
Call the phone number listed in the email signature.
Why it's wrong here
The email's own signature is attacker-controlled, so the number connects to the fraudster, not HR. Verifying via a trusted internal directory is required. Calling a listed number is tempting when a message appears urgent and legitimate, but it only works if the contact details come from an independent, verified source.
Go deeper
Related to this question
Learn chapter
Troubleshoot: Permission Denied Errors
Key term
DomainKeys Identified Mail
DomainKeys Identified Mail is an email authentication method that allows a domain to cryptographically sign its outgoing messages so receiving servers can verify the sender's domain is legitimate and the message was not tampered with.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.