Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user receives an email from an unknown external sender with an attachment named 'Invoice_0934.pdf'. The user is not expecting any invoices. The user reports this to the help desk technician. According to security best practices, what should the technician instruct the user to do?

⚠ Common exam trap

A common mix-up: candidates think forwarding the email as a warning is helpful, but CompTIA emphasizes that only the security team should disseminate alerts to avoid spreading potential threats and to ensure proper incident response procedures are followed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Delete the email and report it to the security team.

The email is a classic phishing attempt: an unsolicited attachment from an unknown sender. Security best practices dictate that the user should not interact with the attachment or sender, and instead delete the email and report it to the security team for analysis and potential blocking of the threat.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Open the attachment to see if it contains any useful information.

    Why it's wrong here

    Opening an unknown attachment can trigger arbitrary code execution through weaponized macros, script embedded in Office documents, or exploits in reader/PDF applications. Even seemingly benign file types carry malware that may install ransomware, keyloggers, or backdoors without further user interaction. This action poses near-instant compromise and should never be performed on unsolicited mail.

  • ✗

    Reply to the sender asking for clarification.

    Why it's wrong here

    Replying to an unknown external sender confirms that the recipient address is monitored and that its owner is susceptible to interaction, making the user a more valuable target for future phishing campaigns. It also gives the attacker an opening to engage in social engineering dialogue or request sensitive data via subsequent messages. Additionally, the reply may leak sender-side metadata and invite follow-up spoofing.

  • ✓

    Delete the email and report it to the security team.

    Why this is correct

    Deleting the email removes the immediate risk of accidental clicks or attachment opens, while reporting it to the security team lets incident handlers preserve the full email header, attachment hash, and embedded URLs as forensic evidence. The security team can then deploy indicators of compromise (IOCs) to the mail gateway and endpoint protection to block similar threats across the organization. This two-step action is the standard, policy-compliant response to unsolicited external email.

  • ✗

    Forward the email to all employees as a warning.

    Why it's wrong here

    Forwarding the email to all employees can amplify the threat by spreading the same malicious attachment or URL to additional mailboxes before any analysis or sanitization is performed. It also strips valuable forensic context—such as the original headers, IP addresses, and routing info—which weakens the security team's investigation. Moreover, sending alerts without security oversight may introduce false panic and bypass the official, vetted warning channel.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.