220-1102 Operational Procedures Practice Question
A technician is investigating a potential security incident. A user reports that they clicked a link in an email and entered their corporate credentials on a website that appeared to be the company's VPN portal. The technician confirms the website is malicious and the credentials have been compromised. According to the company's incident response plan, what should the technician do FIRST?
⚠ Common exam trap
Candidates often choose to disconnect the workstation (Option C) because they focus on network containment rather than credential containment, but the immediate threat is the stolen credentials, not the local device, and the incident response plan prioritizes invalidating the authentication method first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reset the user's password and revoke any active tokens
The first priority in a credential compromise incident is to immediately invalidate the compromised credentials to prevent further unauthorized access. Resetting the user's password and revoking active tokens (such as OAuth tokens or Kerberos TGTs) ensures the attacker can no longer authenticate using the stolen credentials, even if they have already established a session. This aligns with the containment phase of the incident response plan, which must occur before any remediation or documentation steps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Reset the user's password and revoke any active tokens
Why this is correct
Resetting the user's password and revoking all active tokens (e.g., OAuth refresh tokens, session cookies, API keys) is the immediate containment step. Attackers with stolen credentials often retain access through cached tokens or active sessions, so a password change alone may not terminate all valid auth sessions. Revoking tokens ensures that both the password and any bearer credentials issued before the reset are cryptographically invalidated, cutting off the attacker's current access vector.
- ✗
Run a full antivirus scan on the user's workstation
Why it's wrong here
Running a full antivirus scan is a good secondary step, but it does not stop the immediate threat because stolen credentials can be used from any device, not just the user's workstation. Even if malware is found, the attacker would still have valid authentication until the password and tokens are reset. Moreover, an antivirus scan takes time, during which the compromised account remains exploitable, potentially allowing data exfiltration or lateral movement.
- ✗
Disconnect the workstation from the network
Why it's wrong here
Disconnecting the workstation from the network isolates that specific device, which is useful if you suspect an active Remote Access Trojan (RAT) or ongoing malicious network traffic. However, the attacker typically does not need the workstation itself—they can use the stolen credentials from their own system via remote access. Since the credentials are already compromised, network isolation does nothing to revoke the attacker's authentication or prevent them from accessing other systems or cloud services.
- ✗
Document the incident in the ticketing system
Why it's wrong here
Documenting the incident in the ticketing system is a required part of the incident response process, but it is an administrative action that has zero impact on the attacker's currently valid credentials. If documentation is performed first, you are wasting critical time—every second that the password remains unchanged gives the attacker a larger window to move laterally or exfiltrate data. Documentation should occur in parallel with or after the immediate containment steps, not instead of them.
Go deeper
Related to this question
Learn chapter
Network Topology Documentation
Key term
VPN
A VPN creates an encrypted tunnel over a public network to securely connect remote users or sites to a private network.
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.