100-140 Question 340
Single answerAn employee reports receiving an email claiming to be from IT support, asking them to reset their password. The email includes a link to a website that looks similar to the company's login page but has a slightly different URL. What should you do as a first step to investigate and escalate this issue?
- A
Advise the employee to click the link and follow the instructions to reset their password.
- B
Ask the employee to forward the email and URL details to the security team for further analysis.
- C
Immediately delete the email and inform the employee to ignore similar messages in the future.
- D
Access the provided URL yourself to confirm if it is malicious before reporting it.
Show answer and explanation
Correct answer: B
Explanation
When dealing with potential phishing threats, it is important to avoid interacting with suspicious links or emails directly. Instead, the issue should be escalated to the security team with all relevant details (e.g., the email and URL) for proper investigation and mitigation. This protects the user and the organization from potential security breaches.
- A. Incorrect.
Clicking the link and resetting the password could expose the user's credentials to a phishing attack, which is a security risk.
- B. Correct.
Forwarding the email and URL to the security team allows proper investigation and escalation to the appropriate team to handle the potential phishing threat.
- C. Incorrect.
Deleting the email without investigation may prevent the security team from analyzing the threat and protecting other users from similar attacks.
- D. Incorrect.
Accessing the URL yourself could increase the risk of exposing sensitive information or triggering potential malware, which is not a recommended practice.