Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports receiving several emails from an external vendor with malicious attachments. The technician has already removed the offending emails from the user's mailbox and performed a full antivirus scan on the workstation with no detections. Which of the following should the technician do NEXT to prevent future incidents of this nature?

⚠ Common exam trap

The 220-1102 exam often tests the concept that the next step should be a preventive control (blocking the source) rather than a reactive or unrelated action like password changes or law enforcement reporting, which are appropriate only after a confirmed breach or for legal compliance, respectively.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Block the sender's domain in the email filter.

Blocking the sender's domain in the email filter is the most effective immediate step to prevent future incidents because it stops all emails from that domain at the gateway level, before they reach any user's mailbox. Since the antivirus scan found no detections, the threat was likely a social engineering or zero-day attachment that evaded signature-based detection, so blocking the source domain reduces the attack surface without relying on endpoint detection alone.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Block the sender's domain in the email filter.

    Why this is correct

    Blocking the sender's domain in the email filter immediately prevents the specific malicious infrastructure from delivering future messages to users. This is a containment control that reduces the attack surface while the email is quarantined for analysis, and it works even if the sender rotates display names or subjects. Because the domain is a stable attribute of the email's routing path, a filter rule on that domain is a quick, effective response that does not disrupt legitimate communication unless the domain is compromised or spoofed.

  • ✗

    Change the user's password.

    Why it's wrong here

    A password change is appropriate only when there is evidence that the user's credentials were stolen or guessed, such as a successful login from an unfamiliar location or a phishing page that captured the password. In this scenario, the user only received malicious emails; no authentication failure or account takeover has been reported. Forcing a password reset without a compromise indicator introduces avoidable helpdesk overhead and does not stop the incoming malicious messages, so it is not an immediate containment step.

  • ✗

    Report the incident to law enforcement.

    Why it's wrong here

    Law enforcement reporting is a formal process for incident response that may be required under regulations like GDPR or for criminal cases, but it does not actively block the emails or mitigate the current exposure. Immediate security operations should focus on technical controls such as email filtering rules and quarantining, while reporting can be completed in parallel after the immediate threat is contained. Additionally, law enforcement cannot act in real time on a single vendor's malicious email stream to protect your environment, so it is not an urgent first response.

  • ✗

    Train the user on identifying phishing attempts.

    Why it's wrong here

    Phishing-awareness training teaches users to recognize red flags like urgency, mismatched reply-to addresses, and suspicious URL hover-text, which reduces future susceptibility but does nothing to remove the messages already arriving in the mailbox. The incident is ongoing and the user is at risk of clicking a malicious link or attachment right now; a technical filter rule is the only option that immediately interrupts the campaign. Training should be scheduled as a follow-up after the email filter is updated, not as the first action, to avoid leaving the user exposed during the learning process.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.