100-140 Question 352
Select 3You receive an email from what appears to be your company's IT department, asking you to urgently click on a link and confirm your login credentials to avoid account deactivation. How should you respond to avoid being a victim of a social engineering attack?
- A
Verify the sender's email address to ensure it matches the official company domain.
- B
Click the link immediately to check if it is legitimate.
- C
Contact your company's IT department directly using official contact information to confirm the request.
- D
Avoid clicking on any links or downloading attachments from unsolicited emails.
- E
Reply to the email asking for more information to verify its legitimacy.
Show answer and explanation
Correct answers: A, C, D
Explanation
Social engineering attacks often rely on urgency and deception to trick individuals into revealing sensitive information. To avoid becoming a victim, it is crucial to verify the sender's identity, confirm requests through official channels, and refrain from interacting with unsolicited emails. These steps help protect against phishing and other social engineering tactics.
- A. Correct.
Verifying the sender's email address is an important step in identifying phishing attempts, as attackers often use email addresses that look similar but are slightly different from official ones.
- B. Incorrect.
Clicking on the link immediately is risky because it could lead to a phishing website designed to steal your login credentials. This is not a recommended response.
- C. Correct.
Contacting your company's IT department directly through official communication channels is a safe and effective way to verify the legitimacy of such requests.
- D. Correct.
Avoiding clicking on any links or downloading attachments from unsolicited emails is a best practice to prevent falling victim to phishing scams and malware.
- E. Incorrect.
Replying to the email is not a safe option, as it could confirm your email is active to the attacker or lead to further phishing attempts.