220-1102 exam dumps

220-1102 practice question 671 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 671

Single answerResponsible staff members

A company’s security policy states that only designated personnel may approve access changes, handle incident communications, and authorize work on sensitive systems. A technician receives a call from someone claiming to be the CFO who demands an immediate password reset for a payroll system account and asks the technician not to contact anyone else because of an "urgent audit." The caller cannot answer identity-verification questions. What should the technician do NEXT?

  1. A

    Reset the password because the request came from an executive and payroll access is business-critical

  2. B

    Escalate the request to the organization’s responsible staff member or security administrator and follow the documented verification procedure

  3. C

    Email the temporary password to the CFO’s personal email address so work can continue while verification is completed later

  4. D

    Ask a nearby coworker whether the caller sounds legitimate, then proceed if the coworker agrees

Show answer and explanation

Correct answer: B

Explanation

This question tests the candidate’s ability to apply security policy and chain-of-responsibility concepts in a real-world social engineering scenario. In CompTIA A+ Core 2, technicians are expected to recognize when a request must be handled by responsible staff members such as a security administrator, manager, or other designated approver. The correct response is to follow documented identity-verification procedures and escalate when the request involves sensitive systems, exceptions to process, or suspicious behavior. This aligns with common security best practices, including least privilege, change management, and incident handling procedures. A technician should not bypass policy because of claimed urgency, executive status, or pressure from the caller.

  • A. Incorrect.

    This is incorrect. Seniority does not override security policy or identity verification requirements. Resetting a password for a sensitive system without proper validation creates a serious risk of unauthorized access and is a common social engineering trap.

  • B. Correct.

    This is correct. In A+ Core 2 security procedures, technicians should follow established policy, verify identity, and escalate to the appropriate responsible staff member when a request involves sensitive access, exceptions, or potential social engineering. This protects the organization and ensures that only authorized personnel approve the change.

  • C. Incorrect.

    This is incorrect. Sending credentials to a personal email address violates common security best practices and may bypass company controls. It also does not solve the core problem that the caller’s identity has not been verified.

  • D. Incorrect.

    This is incorrect. Informal validation by a coworker is not an approved authentication method. A caller’s tone, urgency, or familiarity is not evidence of identity. Requests involving privileged or sensitive access must be handled through documented procedures and authorized personnel.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam