Courseiva
Security →easyMultiple Choice

220-1102 Security Practice Question

A user receives an email that appears to be from their bank, stating that their account has been compromised and they must click a link to verify their identity. The user notices the sender's email address does not match the bank's official domain. What is the BEST immediate action for the user to take?

⚠ Common exam trap

The 220-1102 exam often tests the misconception that clicking a link to 'verify' the legitimacy is acceptable if the user checks the page, but the trap is that any interaction with the email (including clicking) can compromise security, and the correct action is to report it without interacting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Forward the email to the bank's official customer service or security team

The user should immediately forward the suspicious email to the bank's official security team, who can investigate the phishing attempt and take appropriate action. This aligns with security best practices for handling suspected phishing, as defined in the CompTIA 220-1102 objectives for social engineering and email security. The user should never interact with the email (reply or click links) because the mismatched sender domain is a clear indicator of a phishing attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reply to the email asking the sender to verify their identity

    Why it's wrong here

    Replying to a suspected phishing email is counterproductive because the message is almost certainly not actually from the bank—its display name and forged headers are crafted by the attacker. The reply travels to an address controlled by the attacker, not to the bank's security team, and it confirms that your email address is active, inviting future spear-phishing campaigns. No legitimate bank will ask you to verify identity by replying to an unsolicited message, so this action only aids the attacker.

  • ✗

    Click the link to see if the page looks legitimate

    Why it's wrong here

    Clicking the link in a phishing email is hazardous even if you only intend to 'see if the page looks legitimate.' The URL is often obfuscated with shorteners, homoglyphs, or open redirects, and the landing page may be a pixel-perfect clone of the bank's site designed to harvest credentials. Moreover, simply loading the page can trigger a drive-by download, exploit a browser vulnerability, or install tracking cookies. Visual inspection of a rendered page cannot reveal underlying malicious code, so the action is both deceptive and dangerous.

  • ✓

    Forward the email to the bank's official customer service or security team

    Why this is correct

    Forwarding the email to the bank's official customer service or security team is the correct response because it provides the bank's incident responders with the raw phishing content, including headers that help identify the sending infrastructure. It is critical to use contact information from the bank's official website—not from the email—to ensure the report reaches the legitimate team. This action supports coordinated remediation such as blocking the malicious domain, issuing customer alerts, and initiating a takedown, which protects other customers from the same attack.

  • ✗

    Delete the email and ignore it

    Why it's wrong here

    Deleting the email without reporting it protects only the individual user and leaves the phishing infrastructure active to target other customers. The email contains forensic artifacts—Return-Path headers, originating IP addresses, and the full message body—that a bank's abuse team can analyze to trace the campaign and update email filters. Ignoring the attempt also means you miss the opportunity to alert the bank, so the same phishing lure may continue to circulate and victimize others. Reporting is the safer and more responsible alternative.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.