220-1102 Security Practice Question
A technician receives an unexpected email from the company's Human Resources department with an attachment named 'Employee_Salary_Review.xlsx'. The technician did not request this information and was not expecting any HR communications. According to security best practices, which of the following is the MOST appropriate action for the technician to take?
⚠ Common exam trap
It's easy for candidates to assume a known sender (HR) makes the email safe, but security best practices require verifying unexpected attachments through a separate channel or escalating to security, not trusting the displayed sender name.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Forward the email to the IT security team for investigation
The unexpected email with an unsolicited attachment is a classic phishing indicator. Forwarding it to the IT security team allows them to analyze the attachment and headers for malicious payloads or social engineering tactics, which is the prescribed incident response procedure for suspected phishing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Open the attachment to verify its contents
Why it's wrong here
Opening the attachment is unsafe because email headers and sender addresses can be spoofed, and the attachment may contain a malicious payload such as a macro-enabled document or executable. Even if the sender appears legitimate, the content could trigger a vulnerability or install ransomware. The correct action is to avoid any interaction and preserve the email for security analysis.
- ✓
Forward the email to the IT security team for investigation
Why this is correct
Forwarding the email (preferably as an attachment via the email client's "forward as attachment" feature) preserves the original headers and metadata, allowing the IT security team to perform a forensic analysis of the message, including SPF/DKIM/DMARC checks and static analysis of the attachment in a sandbox. This enables them to identify the phishing campaign, block related indicators of compromise, and warn other users who may have received similar emails.
- ✗
Reply to the sender asking for confirmation
Why it's wrong here
Replying to the email is counterproductive because the "sender" address may be spoofed or a lookalike domain, and any response confirms to the attacker that the mailbox is active, potentially making the technician a target for follow-up spearphishing. Additionally, business email compromise (BEC) attacks often use compromised accounts, so the reply could go to a legitimate but hijacked mailbox, giving the attacker further information about the organization.
- ✗
Delete the email and empty the trash
Why it's wrong here
Deleting the email destroys digital evidence before it can be analyzed, and emptying the trash accelerates that loss. The security team may need the full header and payload to correlate with other IOCs, identify lateral movement, or understand the scope of a phishing campaign, so maintaining the email until the incident is formally closed is a best practice.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.