220-1102 Security Practice Question
A user reports receiving an email that appears to be from their bank asking them to verify their account by clicking a link. The user did not click the link. The technician investigates and confirms the email is a phishing attempt. According to incident response best practices, what should the technician do FIRST?
⚠ Common exam trap
The 220-1102 exam often tests the principle that containment and eradication steps (like deleting emails or blocking domains) must not be performed before the incident is formally reported and analyzed, as candidates may mistakenly think immediate removal is the safest action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the incident to the security team
According to incident response best practices, the first step when a phishing attempt is confirmed is to report the incident to the security team. This ensures proper escalation, containment, and forensic analysis can begin before any evidence is destroyed or compromised. The technician should not take unilateral action like deleting the email or blocking domains without authorization, as that could hinder the investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the phishing email from the user's mailbox
Why it's wrong here
Deleting the phishing email from the user's mailbox is a destructive action that removes the primary forensic artifact needed for incident analysis. The original message contains critical headers, links, and metadata that security analysts rely on to identify the campaign, and deleting it prevents proper investigation. Per incident response procedures, no evidence should be destroyed before the security team has had a chance to examine it, so deletion is only appropriate after reporting and subsequent coordination.
- ✗
Block the sender's email domain at the mail server
Why it's wrong here
Blocking the sender's email domain at the mail server is a tactical containment measure that should never be executed before the incident is reported. The security team must first validate the domain and determine whether it is genuinely malicious or merely spoofed, as many phishing messages use lookalike domains that resemble legitimate organizations. Premature blocking could disrupt benign communications if the address is repurposed, and it bypasses the formal triage process where evidence is preserved and the scope of the campaign is assessed.
- ✓
Report the incident to the security team
Why this is correct
Reporting the phishing attempt to the security team is the mandatory first step in any incident response workflow, as it activates the organization's formal detection and analysis phase. Security personnel will preserve the email as evidence, extract indicators of compromise such as embedded URLs or attachments, and correlate the artifact with other alerts to determine if similar messages were sent to other employees. Timely reporting also allows the team to implement coordinated containment measures before further users are exposed, aligning with frameworks like NIST SP 800-61.
- ✗
Run a full antivirus scan on the user's workstation
Why it's wrong here
Running a full antivirus scan on the workstation is not an appropriate initial response because the user did not interact with the malicious content, meaning the probability of an active infection is extremely low. The scan also does nothing to address the phishing campaign itself, as the same email may still be delivered to other users across the organization. After the security team has analyzed the incident, a scan can be performed as a precautionary measure, but it should not preempt the mandatory reporting step.
Go deeper
Related to this question
Learn chapter
Account Lockout Policies
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.