220-1102 Security Practice Question
A user reports that their email account is sending spam to contacts. The technician identifies that the user's credentials were phished. What is the FIRST step the technician should take?
⚠ Common exam trap
CompTIA often tests the principle of 'containment before eradication' — candidates mistakenly choose to investigate forwarding rules or notify contacts first, but the immediate priority is to cut off the attacker's access to prevent further damage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reset the user's password and force a logout from all sessions
The first priority when credentials are phished is to stop the attacker's access. Resetting the password and forcing logout from all sessions (e.g., revoking tokens via Microsoft Entra ID or Exchange Admin Center) immediately invalidates the compromised credentials and any active sessions, preventing further abuse like sending spam.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on the user's computer
Why it's wrong here
A full antivirus scan addresses malware on the endpoint, but email account compromise often stems from stolen credentials via phishing or credential stuffing, not local malware. Running a scan first leaves the attacker with active access to the mailbox, allowing continued spam and data exfiltration. The scan is a useful secondary step after the account is secured and authenticated sessions are revoked.
- ✓
Reset the user's password and force a logout from all sessions
Why this is correct
Resetting the user's password and forcing a logout from all sessions immediately terminates the attacker's active session tokens and authentication, cutting off the spam source at the account level. This is the critical first step because it contains the breach and prevents further unauthorized use, including mass mailing or forwarding. Even if the password was compromised via a phishing kit, a reset renders that stolen credential useless and invalidates session cookies tied to the old password.
- ✗
Notify all contacts that the user's email was compromised
Why it's wrong here
Notifying contacts that the account was compromised is a reactive communication step, but it does nothing to stop the ongoing spam or revoke the attacker's access. In fact, prematurely notifying contacts before the account is secured could cause confusion, and some contacts might still receive spam during the delay. Account containment must precede any external notification or mitigation to ensure the spam campaign is halted at the source.
- ✗
Check email forwarding rules for unauthorized settings
Why it's wrong here
Checking email forwarding rules helps identify persistence mechanisms the attacker may have set up, but it is an investigative step, not an immediate containment measure. The attacker can still send spam and access the mailbox while you investigate. To stop the active threat, you must first invalidate the session and reset the password; only then can you safely review forwarding rules without the attacker interfering or re-establishing access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.