Courseiva
hardMultiple Choice

220-1102 Practice Question: A technician receives an email that appears to be…

A technician receives an email that appears to be from the company's HR department asking them to click a link to update their direct deposit information. The email contains several grammatical errors and the sender's domain is 'company-hr.com' instead of the official 'company.com'. What is the most effective way to confirm this is a phishing attempt?

⚠ Common exam trap

CompTIA A+ exams often test the principle that verifying suspicious emails through official channels (e.g., security team) is safer than any direct interaction with the email's contents or contacts, and the trap here is that candidates may think calling a listed number is safe, but attackers can spoof phone numbers or use VoIP to appear legitimate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Forward the email to the company's security team for analysis.

Forwarding the suspicious email to the company's security team allows trained analysts to inspect headers, attachments, and URLs in a sandboxed environment without exposing the technician to risk. This aligns with organizational incident response procedures for phishing, as the security team can verify the sender domain (e.g., SPF/DKIM/DMARC failures) and determine if the email is malicious.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reply to the email asking for verification.

    Why it's wrong here

    Replying confirms the address is live and reaches the attacker, who will simply reassure the technician. The sender domain 'company-hr.com' already fails verification against the official 'company.com'. Replying suits routine internal queries, but never validates a suspicious external sender's identity.

  • ✗

    Click the link to see if it looks legitimate.

    Why it's wrong here

    Clicking the link risks credential theft or malware execution and cannot confirm sender authenticity, since phishing pages are designed to look genuine. Clicking is only safe in isolated sandbox environments used for malware analysis, never on a production workstation.

  • ✓

    Forward the email to the company's security team for analysis.

    Why this is correct

    Forwarding the suspicious email to the security team lets trained analysts examine headers, links and sender infrastructure, confirming the phishing attempt without the technician interacting with malicious content. This satisfies the need for authoritative verification rather than relying on visible red flags alone.

  • ✗

    Call the phone number listed in the email signature.

    Why it's wrong here

    The email's own signature is attacker-controlled, so the number connects to the fraudster, not HR. Verifying via a trusted internal directory is required. Calling a listed number is tempting when a message appears urgent and legitimate, but it only works if the contact details come from an independent, verified source.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.