nerdexam
CompTIA

220-1202 · Question #89

SIMULATION 2 As a corporate technician, you are asked to evaluate several suspect email messages on a client's computer. Corporate policy requires the following: - All phishing attempts must be…

The correct classifications are based on key indicators: 'Account Locked' is phishing because it uses a suspicious sender domain ('comptia.co' instead of 'comptia.org') and contains a deceptive 'protect your account' link designed to steal credentials - both classic phishing…

Submitted by alyssa_d· Mar 30, 2026CompTIA Security+ Domain 1: Threats, Attacks and Vulnerabilities - specifically identifying types of social engineering attacks (phishing, spam) and applying appropriate incident response procedures in accordance with organizational security policy.

Question

SIMULATION 2 As a corporate technician, you are asked to evaluate several suspect email messages on a client's computer. Corporate policy requires the following:

  • All phishing attempts must be reported.
  • Future spam emails to users must be prevented.

INSTRUCTIONS Review each email and perform the following within the email:

  • Classify the emails
  • Identify suspicious items, if applicable, in each email
  • Select the appropriate resolution

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button. Answer:

Inbox mail 1 - Account Locked- Phishing - Report email to Information Security Inbox mail 2 - Share your feedback - Legitimate - Perform no additional actions Inbox mail 3 – Employee orientation - Legitimate - Perform no additional actions Inbox mail 4 – Security Update – Spam - Report email to Information Security Inbox mail 5 – Interview - Legitimate - Perform no additional actions

Exhibits

220-1202 question #89 exhibit 1
220-1202 question #89 exhibit 2
220-1202 question #89 exhibit 3
220-1202 question #89 exhibit 4
220-1202 question #89 exhibit 5
220-1202 question #89 exhibit 6

Explanation

The correct classifications are based on key indicators: 'Account Locked' is phishing because it uses a suspicious sender domain ('comptia.co' instead of 'comptia.org') and contains a deceptive 'protect your account' link designed to steal credentials - both classic phishing tactics that must be reported to Information Security per policy. 'Security Update' is spam (unsolicited bulk email) rather than phishing because it lacks targeted credential-harvesting intent, but still requires reporting per corporate policy to prevent future occurrences. The remaining three emails (Share your feedback, Employee orientation, Interview) exhibit no suspicious indicators such as spoofed domains, urgency tactics, or malicious links, making them legitimate with no action required.

Topics

#Phishing Identification#Email Security#Spam vs Phishing Classification#Social Engineering

Community Discussion

No community discussion yet for this question.

Full 220-1202 Practice