220-1102 Operational Procedures Practice Question
A technician is updating the company's standard operating procedure (SOP) for handling phishing emails. Which of the following should be included in the SOP to ensure consistent response?
⚠ Common exam trap
It's easy for candidates to think including the author's name (Option A) adds accountability, but CompTIA tests that SOPs must focus on procedural steps, not administrative metadata, to ensure consistent response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The steps to report the phishing email to the security team.
The SOP for handling phishing emails must include the specific steps to report the incident to the security team. This ensures a consistent, repeatable response across the organization, enabling rapid containment and forensic analysis. Without clear reporting procedures, users might delete the email or forward it to the wrong party, delaying incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The name of the IT manager who authored the SOP.
Why it's wrong here
The SOP's value lies in guiding user behavior, not in documenting project ownership. While the author's name might be useful for questions or updates, it is typically tracked in metadata or version history, not as a step in a phishing-response procedure. Including it would add clutter without helping the user respond to a suspected threat. Therefore, it is not an essential component for this SOP.
- ✓
The steps to report the phishing email to the security team.
Why this is correct
The core of any phishing SOP is a clear, repeatable reporting procedure, because the security team's ability to respond depends on receiving standardized, timely notifications. By specifying exactly how to report, such as forwarding the email as an attachment or using a designated button, the SOP ensures that all users preserve critical evidence and that the incident response team can act without delays. This consistency also enables the security team to track trends and improve defensive controls. For those reasons, this is the required step for the revised SOP.
- ✗
The list of all email addresses in the company.
Why it's wrong here
A company-wide email list is irrelevant to instructing users on phishing response, and embedding such a list in a procedure document creates a serious security liability. If the SOP were leaked or accessed by an attacker, the distribution list would become a direct target for targeted phishing campaigns. Legitimate users already have access to the directory through their email client, so there is no operational need to reproduce it. Thus, this option is wrong because it introduces risk without supporting the reporting workflow.
- ✗
The software version of the email client.
Why it's wrong here
While the email client's software version may be a useful detail for troubleshooting technical issues, it is not a required step in a standardized phishing-response procedure. A phishing SOP focuses on what the user should do, not on the application's build number, which varies across devices and changes frequently. Moreover, requiring users to identify their client version would add friction and delay the critical reporting action. Therefore, this detail is irrelevant to the essential reporting steps.
Go deeper
Related to this question
Learn chapter
Email Security: Spam and Phishing Detection
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Standard Operating Procedure
A Standard Operating Procedure is a detailed, written set of step-by-step instructions that describes how to perform a specific task or process consistently and safely.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.