Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A technician is supporting a remote worker laptop. The immediate goal is to handle suspicious email without clicking links. Which tool, control, or procedure is the best fit?

⚠ Common exam trap

Watch out — candidates often confuse a post-incident recovery tool (System Restore) or a monitoring tool (Event Viewer) with the immediate procedural response required for phishing, rather than recognizing that a reporting process is the first step in the incident response chain.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

phishing reporting process

The phishing reporting process is the correct procedure because it provides a defined workflow for the user to forward or report the suspicious email to the security team without interacting with any links or attachments. This aligns with the immediate goal of handling the threat safely and initiating incident response, as per CompTIA's security best practices for remote workers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Local Users and Groups

    Why it's wrong here

    Local Users and Groups is an administrative snap-in used to manage user accounts, passwords, and group membership on a single Windows device. While it is relevant for troubleshooting account permissions or access issues on a remote laptop, it provides no means to report a phishing email or to escalate a security concern. The immediate goal is to ensure the remote worker's suspicion is conveyed to the security team, so account management would be a distraction from that workflow.

  • ✗

    System Restore

    Why it's wrong here

    System Restore is a Windows feature that reverts system files and registry settings to a previous point in time, commonly used to undo problematic drivers or software installations. It does not address the act of reporting a phishing email, and running it prematurely could destroy forensic evidence needed to analyze the attack. While it might be part of a later remediation step, the immediate priority is to capture and report the phishing attempt, not to change the system state.

  • ✓

    phishing reporting process

    Why this is correct

    The phishing reporting process is the established procedure for a user to forward or flag a suspicious email so that security personnel can analyze it. For a remote worker, this is the immediate and correct action because it provides a safe channel for reporting, enables rapid block of the malicious message, and alerts the organization to the threat. This process is a key part of an organization's incident response and security awareness program, and it directly supports the worker in the moment.

  • ✗

    Event Viewer

    Why it's wrong here

    Event Viewer is a Microsoft Management Console tool for examining application, security, and system logs on a Windows computer. It is useful for diagnosing software or hardware faults, but it is not designed as a user-facing reporting mechanism for phishing attempts. An IT support specialist might later use Event Viewer to look for traces of malicious activity, but the remote worker's immediate need is to submit the phishing email through the proper reporting channel.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.