220-1102 exam dumps

220-1102 practice question 732 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 732

Single answer4.6 Explain the importance of prohibited content/activity and privacy, licensing, and policy concepts.

A technician at a small medical billing company is reimaging an employee's laptop before it is reassigned. While backing up the user's browser data to preserve bookmarks, the technician discovers a folder containing pirated commercial software installers and a spreadsheet with patients' names, dates of birth, and account numbers copied to the desktop. The employee asks the technician to move everything to the new image "so nothing is lost." According to acceptable use, privacy, and licensing best practices, what should the technician do FIRST?

  1. A

    Copy all files as requested, then report the pirated software to management after the migration is complete

  2. B

    Delete the pirated software and spreadsheet immediately so the company is no longer exposed to risk

  3. C

    Stop the migration, avoid accessing unnecessary private data, and escalate the issue according to company policy

  4. D

    Move only the patient spreadsheet because business data takes priority over personal or unlicensed content

Show answer and explanation

Correct answer: C

Explanation

This scenario tests the technician's ability to apply prohibited content/activity, privacy, licensing, and policy concepts in a realistic support situation. Pirated software is a licensing and acceptable use violation, so the technician should not migrate or preserve it. The spreadsheet contains sensitive information that should be handled only under approved processes and with minimum necessary access. In environments handling medical or financial records, technicians should follow company policy, data classification rules, and incident/reporting procedures rather than making ad hoc decisions. A+ Core 2 emphasizes that technicians must recognize prohibited content or activity, respect privacy/confidentiality, and escalate according to organizational policy. This aligns with common best practices such as least privilege, need-to-know access, chain of custody for potentially improper material, and compliance with internal security and acceptable use policies.

  • A. Incorrect.

    This is incorrect because copying the files would transfer unlicensed software and potentially mishandled sensitive information to another system, increasing legal and compliance risk. Even if the technician plans to report it later, proceeding first violates the principle of following policy before taking action on prohibited content or regulated private data.

  • B. Incorrect.

    This is incorrect because the technician should not unilaterally delete data unless authorized by policy or instructed through the proper chain of custody. Immediate deletion could destroy evidence relevant to an internal investigation, violate retention requirements, or create accusations of tampering. The right first step is to stop and escalate.

  • C. Correct.

    This is correct because the technician has encountered both prohibited activity/policy concerns (pirated software, which violates licensing and acceptable use policy) and privacy concerns (patient information that should be handled under need-to-know and data protection rules). Best practice is to stop work that would propagate the issue, limit further exposure of sensitive information, and report through the organization's documented procedures, such as a supervisor, security officer, or compliance contact.

  • D. Incorrect.

    This is incorrect because the spreadsheet contains sensitive patient-related information, and moving it without verifying authorization, business need, and proper handling procedures could create a privacy violation. The fact that it is business-related does not mean the technician should transfer it automatically. The technician must follow policy and proper authorization, especially when regulated or confidential data is involved.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam