100-140 Question 353
Single answerYou receive an unexpected email from what appears to be your company's IT department, requesting you to verify your login credentials by clicking on a link. The email warns that failure to act will result in your account being locked. How should you respond to avoid falling victim to a potential social engineering attack?
- A
Click the link and provide your credentials to ensure your account is not locked.
- B
Reply to the email asking for more information about the request.
- C
Verify the email's legitimacy by contacting your IT department through an official company channel.
- D
Ignore the email, assuming it is a harmless phishing attempt.
Show answer and explanation
Correct answer: C
Explanation
Social engineering attacks often use urgent and seemingly legitimate requests to trick individuals into providing sensitive information. To avoid becoming a victim, always verify the source of suspicious communications through trusted channels, such as directly contacting your IT department. This ensures you do not fall for phishing scams while addressing any genuine concerns.
- A. Incorrect.
Clicking the link and providing your credentials could expose sensitive information to attackers, making this a dangerous choice.
- B. Incorrect.
Replying to the email might confirm your email address as active to attackers, increasing the likelihood of future phishing attempts.
- C. Correct.
Contacting your IT department through an official company channel allows you to confirm whether the email is legitimate without risking sensitive information.
- D. Incorrect.
Ignoring the email might seem safe, but it does not address the potential risk of a legitimate issue or help identify malicious activity.