220-1102 exam dumps

220-1102 practice question 657 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 657

Single answerIncident reports

A help desk technician discovers that an employee opened a malicious email attachment, causing several files on the user's workstation to become encrypted. The technician disconnects the PC from the network and notifies the security team. The incident response lead asks the technician to complete the incident report before handing off the case. Which information is MOST important to include in the incident report to support investigation and possible legal action?

  1. A

    A detailed timeline of observed events, actions taken, affected system information, and the names of personnel involved

  2. B

    The technician's opinion about which external attacker was responsible and how the malware was probably developed

  3. C

    A recommendation to immediately terminate the employee who opened the attachment

  4. D

    A list of all software installed on every workstation in the department, even if unrelated to the incident

Show answer and explanation

Correct answer: A

Explanation

For A+ Core 2, incident reporting emphasizes accurate, objective, and complete documentation. Best practice is to record what was observed, when it occurred, which devices or accounts were affected, what containment actions were taken, and who was involved. Reports should avoid speculation, blame, and irrelevant detail. This aligns with common security incident handling guidance such as documenting date/time stamps, impacted assets, indicators of compromise, actions performed, and escalation steps. In real environments, well-written incident reports help with troubleshooting, forensics, communication between teams, compliance requirements, and potential legal review.

  • A. Correct.

    Correct. Incident reports should contain objective, factual documentation such as the date and time of discovery, symptoms observed, systems affected, containment steps taken, and who performed each action. This information supports investigation, escalation, and chain-of-custody style tracking. It is also useful if the event leads to disciplinary review, insurance claims, or legal proceedings.

  • B. Incorrect.

    Incorrect. An incident report should focus on verifiable facts, not speculation. Guessing about the attacker or malware origin can introduce inaccurate information and weaken the quality of the report. Attribution is typically handled later by security analysts, forensic investigators, or law enforcement using evidence.

  • C. Incorrect.

    Incorrect. Personnel recommendations, especially disciplinary conclusions, are not the primary purpose of an incident report. The report should document what happened and what actions were taken, not make unsupported HR decisions. Including emotional or punitive statements reduces professionalism and objectivity.

  • D. Incorrect.

    Incorrect. An incident report should be relevant and scoped to the event. Including unrelated software inventories from unaffected systems adds noise and can make the report harder to use. Only systems, applications, and data directly related to the incident should be documented unless broader impact is confirmed.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam