Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A technician receives an email that appears to come from the company's HR department, stating that all employees must update their direct deposit information immediately by clicking a link and authenticating with their corporate credentials. The sender's email address is 'hr@cornpany.com' (note the 'rn' instead of 'm'). The technician suspects a phishing attack. What should the technician do FIRST?

⚠ Common exam trap

Test-takers frequently think deleting the email is safest, but the CompTIA 220-1102 exam emphasizes reporting phishing to the security team as the correct first step to protect the entire organization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Forward the email to the company's security team

The first step when a phishing email is suspected is to report it to the company's security team. This allows the security team to analyze the email headers, the malicious link, and the spoofed domain (e.g., 'cornpany.com' vs. 'company.com') to block the threat and warn other employees. Forwarding the email preserves the original headers and metadata, which are critical for forensic analysis and for updating email security filters.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Forward the email to the company's security team

    Why this is correct

    Forwarding the email to the security team preserves the original message headers, including the originating IP, authentication results (SPF/DKIM/DMARC), and routing data, which are critical for tracing the source and identifying the attack infrastructure. The security team can extract malicious indicators such as the sender address, embedded URLs, and attachments, block them at the gateway, and issue an organization-wide advisory. This turns an individual suspicious message into actionable threat intelligence rather than a lost artifact.

  • ✗

    Delete the email immediately

    Why it's wrong here

    Deleting the email removes it from the technician's inbox but destroys the only forensic evidence available for analysis, leaving the security team blind to the specific phishing indicators and unable to determine whether similar messages have targeted other employees. The attacker's infrastructure remains unblocked, so the same campaign continues spreading to other mailboxes and may eventually result in a breach. Secure deletion also fails to report the incident to the proper escalation channel, violating standard incident-response procedures.

  • ✗

    Click the link but do not enter any credentials

    Why it's wrong here

    Clicking the link, even without entering credentials, initiates an HTTP/S request to the attacker's server, which can execute a drive-by download that exploits unpatched browser, plugin, or PDF-reader vulnerabilities to deliver ransomware or spyware. The request itself also reveals the recipient's IP address, user-agent, and active email address, enabling the attacker to confirm the target and tailor follow-up campaigns. Additionally, many phishing links use URL shorteners or compromised legitimate domains that redirect to malicious payloads automatically, so simply visiting the URL is never safe.

  • ✗

    Reply to the email asking for verification

    Why it's wrong here

    Replying to the email establishes direct communication with the attacker and confirms that the email address is actively monitored and the recipient is willing to respond, which increases the perceived value of the target for future spear-phishing or business email compromise (BEC) attacks. The attacker may manually engage in conversation, using social engineering to extract sensitive information, passwords, or credentials under the guise of legitimate requests. Furthermore, a reply can bypass automated security filters that flagged the original message as spam, since a two-way conversation often appears less suspicious to email gateways.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A technician receives an email at work that appears to come from the company's payroll department. The email states that the recipient must verify their direct deposit information by clicking a link and logging in with their corporate credentials. The technician notices the sender's email address is 'payroll@cornpany.com' instead of 'payroll@company.com'. What is the BEST first action for the technician to take?

medium
  • A.Click the link to see if the website looks legitimate
  • ✓ B.Forward the email to the company's security team for investigation
  • C.Delete the email and ignore it
  • D.Reply to the email asking for clarification

Why B: The email exhibits classic signs of a phishing attack: a spoofed sender domain ('cornpany.com' vs. 'company.com') and a request to verify credentials via a link. The best first action is to report it to the security team, who can analyze the threat, block the domain, and warn other users. Clicking the link or simply deleting the email without reporting could expose the technician or others to credential theft or malware.

Variation 2. A user receives an email that appears to be from the company's HR department, asking the user to click a link and enter their login credentials to view a new benefits document. The technician notices the sender's domain is 'hr@cornpany.com' (with 'rn' instead of 'm'). The user did not click the link. According to best practices, what should the technician do FIRST?

medium
  • A.A. Reply to the email to verify the sender's identity.
  • ✓ B.B. Report the email to the IT security team as a phishing attempt.
  • C.C. Block the sender's email address on the user's mailbox.
  • D.D. Instruct the user to delete the email and ignore it.

Why B: The email exhibits classic phishing indicators: a spoofed sender domain ('cornpany.com' instead of 'company.com') and a request for login credentials via a link. According to security best practices, the first action should be to report the suspicious email to the IT security team so they can analyze the threat, block the sender, and alert other users. Replying to the email could confirm the address is active or expose the user to further social engineering, and ignoring it leaves the threat unaddressed.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.