220-1102 Operational Procedures Practice Question
A technician is documenting a security incident in which a user's company-issued laptop was stolen. The technician has already reported the theft to the security team and initiated a remote wipe of the device. According to incident response best practices, what should the technician do NEXT?
⚠ Common exam trap
A common mix-up: candidates confuse the urgency of legal actions (like filing a police report) with the structured incident response workflow, but CompTIA emphasizes that documentation is the immediate next step after containment and eradication, not external reporting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a detailed incident report.
After reporting the theft and initiating a remote wipe, the next step in incident response best practices is to create a detailed incident report. This report documents the who, what, when, where, and how of the incident, which is essential for legal, insurance, and compliance purposes. It also serves as a record for post-incident analysis and helps improve future security measures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a root cause analysis.
Why it's wrong here
Root cause analysis (RCA) is a structured investigation to identify underlying system or process weaknesses, using techniques such as 5 Whys or fault tree analysis. However, RCA is a deliberate post-incident review activity that occurs during the lessons-learned phase, not immediately after containment. At this moment, the priority is preserving the current state and recording facts, since RCA relies on accurate, contemporaneous documentation to be meaningful.
- ✗
File a police report.
Why it's wrong here
Filing a police report is appropriate only when the incident involves criminal activity (e.g., theft, fraud) and is typically the responsibility of management, legal counsel, or the security team after consulting law enforcement. A technician's immediate duty is to preserve evidence and document the incident, not to make external legal notifications. Premature reporting without organizational approval could violate privacy laws or breach incident-handling procedures.
- ✓
Create a detailed incident report.
Why this is correct
Creating a detailed incident report is the correct immediate next step because it captures the timeline, scope, impact, actions taken, and evidence collected during containment, which is essential for compliance, legal defense, and future prevention. This documentation preserves the chain of custody and provides the factual basis for root cause analysis, eradication, and recovery. Without it, critical details may be lost and regulatory reporting deadlines missed.
- ✗
Replace the laptop immediately.
Why it's wrong here
Immediately replacing the laptop is premature because the original device must undergo forensic imaging and evidence preservation before any hardware is swapped out, especially if the incident involved a data breach. Replacement is part of the recovery phase and should follow an approved change-management procedure, with the incident report already documenting the device's role in the incident. Rushing to replace can destroy volatile evidence and violate evidence-handling requirements.
Go deeper
Related to this question
Learn chapter
Incident Response for A+
Key term
Wipe
Wipe is the process of securely erasing all data from a storage device, making it unrecoverable and preparing the device for reuse or disposal.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.