220-1102 Security Practice Question
A user receives an email that appears to be from their bank, stating that their account has been compromised and they must click a link to verify their identity. The user notices the sender's email address does not match the bank's official domain. What is the BEST immediate action for the user to take?
⚠ Common exam trap
The 220-1102 exam often tests the misconception that clicking a link to 'verify' the legitimacy is acceptable if the user checks the page, but the trap is that any interaction with the email (including clicking) can compromise security, and the correct action is to report it without interacting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Forward the email to the bank's official customer service or security team
The user should immediately forward the suspicious email to the bank's official security team, who can investigate the phishing attempt and take appropriate action. This aligns with security best practices for handling suspected phishing, as defined in the CompTIA 220-1102 objectives for social engineering and email security. The user should never interact with the email (reply or click links) because the mismatched sender domain is a clear indicator of a phishing attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reply to the email asking the sender to verify their identity
Why it's wrong here
Replying to a suspected phishing email is counterproductive because the message is almost certainly not actually from the bank—its display name and forged headers are crafted by the attacker. The reply travels to an address controlled by the attacker, not to the bank's security team, and it confirms that your email address is active, inviting future spear-phishing campaigns. No legitimate bank will ask you to verify identity by replying to an unsolicited message, so this action only aids the attacker.
- ✗
Click the link to see if the page looks legitimate
Why it's wrong here
Clicking the link in a phishing email is hazardous even if you only intend to 'see if the page looks legitimate.' The URL is often obfuscated with shorteners, homoglyphs, or open redirects, and the landing page may be a pixel-perfect clone of the bank's site designed to harvest credentials. Moreover, simply loading the page can trigger a drive-by download, exploit a browser vulnerability, or install tracking cookies. Visual inspection of a rendered page cannot reveal underlying malicious code, so the action is both deceptive and dangerous.
- ✓
Forward the email to the bank's official customer service or security team
Why this is correct
Forwarding the email to the bank's official customer service or security team is the correct response because it provides the bank's incident responders with the raw phishing content, including headers that help identify the sending infrastructure. It is critical to use contact information from the bank's official website—not from the email—to ensure the report reaches the legitimate team. This action supports coordinated remediation such as blocking the malicious domain, issuing customer alerts, and initiating a takedown, which protects other customers from the same attack.
- ✗
Delete the email and ignore it
Why it's wrong here
Deleting the email without reporting it protects only the individual user and leaves the phishing infrastructure active to target other customers. The email contains forensic artifacts—Return-Path headers, originating IP addresses, and the full message body—that a bank's abuse team can analyze to trace the campaign and update email filters. Ignoring the attempt also means you miss the opportunity to alert the bank, so the same phishing lure may continue to circulate and victimize others. Reporting is the safer and more responsible alternative.
Go deeper
Related to this question
Learn chapter
Account Lockout Policies
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.