Courseiva
Security →easyMultiple Choice

220-1102 Security Practice Question

A technician sees a person wearing a visitor badge wandering alone in a secure server room. According to security best practices, which of the following should the technician do first?

⚠ Common exam trap

Many candidates choose Option A (confront directly) because they think it shows initiative, but CompTIA emphasizes that unarmed technicians should never engage potential threats and must always defer to security professionals.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Report the person to security

The immediate priority in a secure server room is to ensure physical security by notifying authorized security personnel. The technician should not confront or challenge the visitor directly, as that could escalate the situation or put the technician at risk. Reporting to security follows established incident response protocols for unauthorized access, as outlined in CompTIA Security+ and 220-1102 objectives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Confront the person directly

    Why it's wrong here

    Direct confrontation by a technician can escalate an unknown situation, potentially provoking a hostile response or alerting an intruder. It places an untrained individual in harm's way and bypasses established security protocols. The proper chain is to report to security, who have the authority and training to assess and intervene safely.

  • ✗

    Ignore the situation

    Why it's wrong here

    Ignoring a visitor without proper credentials allows a potential unauthorized individual to remain in restricted areas, creating a risk to data, equipment, and personnel. It contradicts an organization's incident response and security awareness policies, which mandate reporting suspicious activity. Even if the person is benign, the failure to report erodes the security culture and could enable a serious breach.

  • ✗

    Ask for identification

    Why it's wrong here

    Asking for identification is a reasonable step to gather information, but it is insufficient on its own because the technician is not authorized to verify credentials, issue access, or enforce security policy. The visitor might present fake or unvalidated ID, and the technician would have no way to confirm its legitimacy. The correct action is to report to security, who can properly verify identity, check access rights, and take appropriate action while the technician continues with their duties.

  • ✓

    Report the person to security

    Why this is correct

    Reporting the visitor to security is the correct response because it activates the proper incident-response channel and places the situation in the hands of trained professionals who have the authority to investigate, verify, and act. It ensures that any potential security threat is documented and handled according to organizational policy, protecting both the technician and the organization. This aligns with the principle of "see something, say something" without assuming the risk of direct intervention.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.