220-1102 Security Practice Question
A technician is entering a secured server room using their badge. They notice an unfamiliar person slips in behind them before the door closes, without using any credentials. The person is wearing a lanyard with a generic company logo but no visible photo ID. Which of the following actions should the technician take FIRST?
⚠ Common exam trap
Many candidates choose to confront the intruder directly (Option A) due to a sense of responsibility, but CompTIA emphasizes that the first action should always be to notify security or a supervisor to avoid personal risk and ensure a proper security response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Immediately notify security and/or a supervisor about the incident.
Tailgating is a physical security breach where an unauthorized person gains access by following an authorized individual. The technician's first priority is to report the incident immediately to security or a supervisor, as per standard security protocols, to initiate a proper response and prevent potential data theft or sabotage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Politely ask the person to leave and escort them to the front desk.
Why it's wrong here
Politely asking an unknown person to leave and escorting them out places the technician in an unsafe and unauthorized role. Engaging with a potential intruder could provoke a physical confrontation or allow them to slip away before security is alerted. The correct protocol is to never intervene directly, but to observe and report the situation to personnel trained in access control and incident response.
- ✓
Immediately notify security and/or a supervisor about the incident.
Why this is correct
Immediately notifying security or a supervisor activates the incident response chain of command, ensuring that trained personnel can verify the individual's identity, review badge logs and surveillance footage, and take lawful action if needed. This preserves evidence, protects the technician from personal risk, and fulfills organizational security policy. Even if the person is later found to be authorized, reporting a suspected breach is always the correct action.
- ✗
Continue to the server and perform the scheduled maintenance, ignoring the person.
Why it's wrong here
Continuing with scheduled maintenance while ignoring an unrecognized person in a secured server room leaves sensitive infrastructure exposed to potential theft, sabotage, or unauthorized data access. It also normalizes a security breach, and the technician's focus on the server may miss signs of suspicious behavior. This violates the principle of maintaining continuous awareness of the physical security environment during any work in restricted areas.
- ✗
Ask the person for their employee ID number and verify in the directory.
Why it's wrong here
Asking for an employee ID and attempting to verify it in a directory is beyond the technician's authority and skill set, and the person could easily present forged credentials or use social engineering to avoid scrutiny. The directory may not be accessible from the server room, and the technician has no way to confirm the ID is genuinely linked to the person. This approach delays the proper escalation to security, who have the tools and training to conduct a credible verification.
Go deeper
Related to this question
Learn chapter
Data Classification Levels
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.