100-140 Question 341
Select 2A user reports receiving an email that appears to be from their bank, asking them to click on a link to confirm their account information. Upon investigation, you notice the email contains poor grammar and a suspicious URL. What should you do next?
- A
Advise the user not to click on any links or respond to the email.
- B
Perform a detailed forensic analysis of the user's computer to check for malware.
- C
Capture screenshots of the email and report it to your organization's security team.
- D
Delete the email immediately without taking further action.
- E
Verify the legitimacy of the email by contacting the bank using the phone number provided in the email.
Show answer and explanation
Correct answers: A, C
Explanation
Phishing emails are a common security threat. Users should be advised not to engage with suspicious emails, and IT support technicians should document and escalate the issue to the appropriate security team for further investigation. Deleting the email or using potentially fraudulent contact information are unsafe practices.
- A. Correct.
This is the correct course of action to prevent the user from falling victim to the phishing attempt.
- B. Incorrect.
While detailed forensic analysis is not necessary at this stage, escalating to the appropriate team is more appropriate.
- C. Correct.
This is the correct action to document the potential phishing threat and escalate it to the security team.
- D. Incorrect.
Deleting the email immediately without taking further action is incorrect, as it prevents proper escalation and documentation of the threat.
- E. Incorrect.
Contacting the bank using the phone number provided in the email is unsafe, as the number could also be fraudulent.