220-1102 Operational Procedures Practice Question
A technician discovers that a user has installed a game application on their company workstation, which violates the company's acceptable use policy. What is the technician's first action according to standard operational procedures?
⚠ Common exam trap
Many exam-takers think the technician should immediately fix the problem (uninstall the game) rather than follow the proper escalation procedure, which is a common mistake in operational procedure questions that test chain-of-command and incident response protocols.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the violation to the user's manager or the IT security team
Standard operational procedures for security incidents require the technician to first report the policy violation to the user's manager or the IT security team. This ensures that the incident is formally documented and escalated according to the company's incident response plan, rather than the technician taking unilateral action that could violate chain-of-command or legal requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Report the violation to the user's manager or the IT security team
Why this is correct
The proper security response is to escalate the incident through the designated chain of command. By reporting the violation to the user's manager or the IT security team, you ensure the issue is officially documented and handled according to corporate policy, preserving any needed evidence and allowing the appropriate disciplinary or remediation actions to be taken at the correct authority level.
- ✗
Uninstall the game and warn the user not to install unapproved software again
Why it's wrong here
Directly uninstalling the game without first reporting the violation exceeds the technician's authority and bypasses the formal incident response process. This action could destroy potential digital evidence if the application is actually malicious or contains traces of data exfiltration, and it undermines management's right to determine consequences; the technician's duty is to escalate, not to execute unauthorized remediation.
- ✗
Ignore the violation because the game is not causing any performance issues
Why it's wrong here
Ignoring the violation because the game appears to be causing no performance issues is a flawed justification because security risk is not limited to performance degradation. Unapproved software can harbor malware, create backdoors, violate software licensing, or lead to data breaches without any visible performance impact, and tolerating such violations establishes a dangerous precedent that weakens the entire security posture.
- ✗
Create a new policy allowing games during lunch breaks
Why it's wrong here
As a technician, you have no authority to create or modify corporate acceptable-use policies; that process requires formal change management and approval from management, HR, and legal. Even if a new policy were legitimate, it would not excuse the user's existing violation, and allowing games introduces unnecessary risk and liability, so the only proper action is to report the incident rather than attempt to rewrite policy.
Go deeper
Related to this question
Learn chapter
Group Policy for A+
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.