Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports that they received a phone call from someone claiming to be from the company's IT help desk. The caller stated there was a security issue and requested the user's login credentials and a multi-factor authentication (MFA) code. The user provided the information. Which of the following should the technician do FIRST as part of the incident response?

⚠ Common exam trap

Many candidates choose to run an antivirus scan or check logs first, thinking they need to investigate the attack, but the CompTIA 220-1102 exam emphasizes that immediate containment (disabling the account) is the priority over forensic analysis or data protection measures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable the user's account and force a password reset

The correct first step is to disable the user's account and force a password reset because the user has already compromised their credentials and MFA code, giving the attacker immediate access. This aligns with the NIST SP 800-61 incident response framework's containment phase, which prioritizes stopping further unauthorized access before any other action. By disabling the account, you prevent the attacker from using the stolen credentials to authenticate to any network resources, including VPN, email, or domain services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Disable the user's account and force a password reset

    Why this is correct

    Disabling the user's account is the immediate containment step because the attacker already possesses valid credentials and an active MFA session—this invalidates the authentication token and prevents further access to network resources. A forced password reset ensures that even if the attacker has cached credentials or a persisted session, the real user’s next login establishes a fresh, secure authentication baseline. Delaying containment to perform other actions gives the attacker additional time to move laterally or exfiltrate data.

  • ✗

    Enable full disk encryption on the user's workstation

    Why it's wrong here

    Full disk encryption (FDE) such as BitLocker protects data at rest by rendering the hard drive unreadable without the encryption keys, but it does nothing to stop an attacker who is already operating in the user's context with valid credentials. Since the attacker has an active MTA session and is likely accessing resources over the network, FDE is irrelevant to the immediate threat. FDE is a proactive security control that should already be deployed as a baseline, not a reactive emergency response to a confirmed credential compromise.

  • ✗

    Run a full antivirus scan on the user's workstation

    Why it's wrong here

    Running a full antivirus scan treats the incident as a malware infestation, but the evidence points to an attacker using legitimate credentials—not necessarily malicious code on the workstation. Even if malware is present, scanning is a secondary step that takes time and may provide the attacker with additional opportunity to misuse the account. The priority must be to cut off the attacker's access; malware analysis can safely occur only after containment, as scanning won't invalidate stolen credentials or kill the attacker's existing session.

  • ✗

    Check the domain controller logs for any evidence of lateral movement

    Why it's wrong here

    Checking domain controller logs for lateral movement is a forensic activity that helps determine the breadth of the compromise, but it does not contain the active threat. The attacker may be using the compromised user's credentials to pivot across systems while you're reviewing logs, and they might even be tampering with or deleting those logs if they have administrative privileges. Proper incident response order dictates that you contain the breach first by disabling the account, then preserve and analyze logs as evidence after the immediate risk is neutralized.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.