100-140 Question 337
Select 3You are working as an IT support technician for a small company, and an employee reports receiving an email that claims to be from the IT department asking for their login credentials to resolve a 'security issue.' The email contains spelling errors and a suspicious link. What steps should you take to address this scenario?
- A
Instruct the employee to immediately provide their credentials to the sender to resolve the issue quickly.
- B
Advise the employee to avoid clicking the link and report the email to the IT security team.
- C
Flag the email as spam or phishing in the email client and delete it.
- D
Conduct a company-wide email to inform others of the potential phishing attempt.
- E
Ignore the report since it is likely a false alarm.
Show answer and explanation
Correct answers: B, C, D
Explanation
Phishing emails are a common threat that can compromise sensitive information. Proper prevention steps include reporting the email to the IT team, flagging it as phishing, and informing others of the threat. These actions help mitigate potential risks and maintain organizational security.
- A. Incorrect.
This is incorrect. Providing credentials to unknown or suspicious sources compromises security and could lead to unauthorized access.
- B. Correct.
This is correct. Advising the employee to avoid interacting with the email and reporting it helps prevent potential security breaches.
- C. Correct.
This is correct. Flagging the email within the client helps improve email filtering and reduces the risk for other users.
- D. Correct.
This is correct. Informing others about the phishing attempt creates awareness and prevents other employees from falling victim to the same threat.
- E. Incorrect.
This is incorrect. Ignoring the report could allow the phishing attempt to succeed with other employees, leading to a potential security breach.