220-1102 exam dumps

220-1102 practice question 426 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 426

Single answerAntiphishing training

A company's help desk has noticed several employees clicking links in fake package-delivery emails and then calling support because they entered their passwords on look-alike websites. Management asks the IT technician to recommend the MOST effective antiphishing training approach to reduce repeat incidents. Which of the following should the technician recommend?

  1. A

    Send a one-time email reminding users not to click suspicious links

  2. B

    Implement recurring simulated phishing campaigns with immediate feedback and short follow-up training

  3. C

    Block all external email messages that contain hyperlinks

  4. D

    Require employees to change their passwords every week

Show answer and explanation

Correct answer: B

Explanation

The best answer is to use recurring simulated phishing exercises combined with immediate coaching and short refresher training. For A+ Core 2, antiphishing training is not just about telling users to be careful; it is about creating a repeatable awareness program that teaches users to identify suspicious senders, mismatched URLs, unexpected requests, urgency, spoofing, and credential-harvesting behavior. Industry guidance, including security awareness recommendations from organizations such as NIST, supports ongoing role-appropriate awareness training and reinforcing secure behavior through practice and feedback. This approach is more effective than one-time reminders, unrealistic technical bans, or unrelated password changes.

  • A. Incorrect.

    This is not the most effective approach. A one-time reminder may raise awareness briefly, but phishing resistance improves more when training is ongoing, measurable, and reinforced over time. Users often forget general reminders, especially if they are not tied to realistic examples or immediate coaching.

  • B. Correct.

    This is correct. Recurring simulated phishing campaigns test users in realistic scenarios and help identify risky behavior. Immediate feedback and brief targeted training reinforce how to spot red flags such as spoofed domains, urgent language, unexpected attachments, and credential-harvest pages. This aligns with common security-awareness best practices: regular education, testing, and reinforcement rather than a single annual or ad hoc message.

  • C. Incorrect.

    This is incorrect because it is overly disruptive and not a practical training strategy. Many legitimate business emails contain links, so blocking all external hyperlinks would interfere with normal operations. It also avoids the user education problem rather than improving users' ability to recognize phishing attempts across email, messaging, and web interactions.

  • D. Incorrect.

    This is incorrect. Frequent password changes do not address the root cause of users being tricked into submitting credentials to phishing sites. While password policy is part of account security, antiphishing training should focus on recognizing suspicious messages, verifying requests, and reporting suspected phishing attempts. Excessively frequent password changes can also lead to weaker password habits.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam