220-1102 exam dumps

220-1102 practice question 433 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 433

Single answerQR code phishing

An employee reports receiving a printed flyer in the office break room that says, "Mandatory payroll update - scan this QR code to avoid direct deposit interruption." After scanning it with a personal smartphone, the employee is taken to a login page that looks similar to the company's Microsoft 365 sign-in screen. The employee has not entered any credentials yet and asks the help desk what to do next. Which action should the technician recommend FIRST to reduce risk from this likely QR code phishing attempt?

  1. A

    Tell the employee to close the page, avoid entering credentials, and report the flyer and QR code to security so it can be investigated and removed

  2. B

    Tell the employee to continue to the site and verify whether the page accepts their corporate password

  3. C

    Tell the employee to factory reset the smartphone immediately because scanning a QR code means the device is already infected

  4. D

    Tell the employee to disconnect the office Wi-Fi access point until the source of the QR code is identified

Show answer and explanation

Correct answer: A

Explanation

This scenario tests recognition of QR code phishing in a realistic workplace setting. In A+ Core 2, candidates are expected to identify phishing-related attacks and apply practical incident response steps. A QR code can hide a malicious URL and is often used to bypass a user's normal caution because the destination is not obvious before scanning. The best first action is to stop the user from proceeding, ensure no credentials are entered, and report the item through the organization's security or incident process so the physical lure can be removed and investigated. If the employee had already entered credentials, additional steps would include changing the password, reviewing MFA status, and notifying the security team immediately. This aligns with common security awareness guidance from organizations such as CISA and Microsoft, which emphasize verifying unexpected login prompts, avoiding untrusted links and QR codes, and reporting suspected phishing attempts promptly.

  • A. Correct.

    This is the best first response. QR code phishing, often called quishing, commonly redirects users to credential-harvesting pages that imitate trusted login portals. Because the employee has not entered credentials, the immediate priority is to stop interaction with the site, preserve the employee's account security, and escalate the suspicious flyer for investigation and removal. Reporting also helps protect other users who might scan the same code.

  • B. Incorrect.

    This is incorrect because it instructs the user to interact further with a suspicious page. Testing whether a login works would expose credentials to a likely phishing site. A key security best practice is to avoid entering usernames, passwords, or MFA information into links or pages reached through untrusted QR codes, emails, texts, or printed materials.

  • C. Incorrect.

    This is incorrect because scanning a QR code by itself does not automatically mean the phone is infected. A QR code usually just encodes data such as a URL. While malicious sites can lead to harmful outcomes, a factory reset is not the first or most appropriate response when no credentials were entered and no confirmed malware activity is present. This option reflects an exaggerated response.

  • D. Incorrect.

    This is incorrect because the issue is a suspicious social engineering lure, not evidence that the wireless infrastructure is compromised. Disabling the office Wi-Fi would be disruptive and would not address the printed flyer itself. The proper first step is user containment and incident reporting, not network-wide shutdown.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam