Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A technician is entering a secured server room using their badge. They notice an unfamiliar person slips in behind them before the door closes, without using any credentials. The person is wearing a lanyard with a generic company logo but no visible photo ID. Which of the following actions should the technician take FIRST?

⚠ Common exam trap

Many candidates choose to confront the intruder directly (Option A) due to a sense of responsibility, but CompTIA emphasizes that the first action should always be to notify security or a supervisor to avoid personal risk and ensure a proper security response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Immediately notify security and/or a supervisor about the incident.

Tailgating is a physical security breach where an unauthorized person gains access by following an authorized individual. The technician's first priority is to report the incident immediately to security or a supervisor, as per standard security protocols, to initiate a proper response and prevent potential data theft or sabotage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Politely ask the person to leave and escort them to the front desk.

    Why it's wrong here

    Politely asking an unknown person to leave and escorting them out places the technician in an unsafe and unauthorized role. Engaging with a potential intruder could provoke a physical confrontation or allow them to slip away before security is alerted. The correct protocol is to never intervene directly, but to observe and report the situation to personnel trained in access control and incident response.

  • ✓

    Immediately notify security and/or a supervisor about the incident.

    Why this is correct

    Immediately notifying security or a supervisor activates the incident response chain of command, ensuring that trained personnel can verify the individual's identity, review badge logs and surveillance footage, and take lawful action if needed. This preserves evidence, protects the technician from personal risk, and fulfills organizational security policy. Even if the person is later found to be authorized, reporting a suspected breach is always the correct action.

  • ✗

    Continue to the server and perform the scheduled maintenance, ignoring the person.

    Why it's wrong here

    Continuing with scheduled maintenance while ignoring an unrecognized person in a secured server room leaves sensitive infrastructure exposed to potential theft, sabotage, or unauthorized data access. It also normalizes a security breach, and the technician's focus on the server may miss signs of suspicious behavior. This violates the principle of maintaining continuous awareness of the physical security environment during any work in restricted areas.

  • ✗

    Ask the person for their employee ID number and verify in the directory.

    Why it's wrong here

    Asking for an employee ID and attempting to verify it in a directory is beyond the technician's authority and skill set, and the person could easily present forged credentials or use social engineering to avoid scrutiny. The directory may not be accessible from the server room, and the technician has no way to confirm the ID is genuinely linked to the person. This approach delays the proper escalation to security, who have the tools and training to conduct a credible verification.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.