Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A technician is updating the company's standard operating procedure (SOP) for handling phishing emails. Which of the following should be included in the SOP to ensure consistent response?

⚠ Common exam trap

It's easy for candidates to think including the author's name (Option A) adds accountability, but CompTIA tests that SOPs must focus on procedural steps, not administrative metadata, to ensure consistent response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The steps to report the phishing email to the security team.

The SOP for handling phishing emails must include the specific steps to report the incident to the security team. This ensures a consistent, repeatable response across the organization, enabling rapid containment and forensic analysis. Without clear reporting procedures, users might delete the email or forward it to the wrong party, delaying incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The name of the IT manager who authored the SOP.

    Why it's wrong here

    The SOP's value lies in guiding user behavior, not in documenting project ownership. While the author's name might be useful for questions or updates, it is typically tracked in metadata or version history, not as a step in a phishing-response procedure. Including it would add clutter without helping the user respond to a suspected threat. Therefore, it is not an essential component for this SOP.

  • ✓

    The steps to report the phishing email to the security team.

    Why this is correct

    The core of any phishing SOP is a clear, repeatable reporting procedure, because the security team's ability to respond depends on receiving standardized, timely notifications. By specifying exactly how to report, such as forwarding the email as an attachment or using a designated button, the SOP ensures that all users preserve critical evidence and that the incident response team can act without delays. This consistency also enables the security team to track trends and improve defensive controls. For those reasons, this is the required step for the revised SOP.

  • ✗

    The list of all email addresses in the company.

    Why it's wrong here

    A company-wide email list is irrelevant to instructing users on phishing response, and embedding such a list in a procedure document creates a serious security liability. If the SOP were leaked or accessed by an attacker, the distribution list would become a direct target for targeted phishing campaigns. Legitimate users already have access to the directory through their email client, so there is no operational need to reproduce it. Thus, this option is wrong because it introduces risk without supporting the reporting workflow.

  • ✗

    The software version of the email client.

    Why it's wrong here

    While the email client's software version may be a useful detail for troubleshooting technical issues, it is not a required step in a standardized phishing-response procedure. A phishing SOP focuses on what the user should do, not on the application's build number, which varies across devices and changes frequently. Moreover, requiring users to identify their client version would add friction and delay the critical reporting action. Therefore, this detail is irrelevant to the essential reporting steps.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.