100-140 exam dumps

100-140 practice question 357 of 390

Cisco Certified Support Technician (CCST) IT Support. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-140 Question 357

Select 3

A user in your organization receives an email claiming to be from the IT department, asking them to urgently reset their password by clicking a link. The email appears legitimate but contains spelling errors and a suspicious URL. What steps should the user take to verify the authenticity of the email and avoid falling victim to a phishing attack?

  1. A

    Contact the IT department directly using a known, official communication channel to confirm the request.

  2. B

    Click the link in the email to check if it leads to a legitimate website.

  3. C

    Inspect the sender's email address for any discrepancies or unusual domains.

  4. D

    Forward the email to a trusted colleague to confirm if they received the same email.

  5. E

    Report the email to your organization's security or IT team as a potential phishing attempt.

Show answer and explanation

Correct answers: A, C, E

Explanation

Phishing emails often use urgency and social engineering tactics to trick users into clicking malicious links or sharing sensitive information. To avoid falling victim, users should verify requests through official channels, inspect email addresses for signs of impersonation, and promptly report suspicious emails to the appropriate teams. Clicking on suspicious links or forwarding the email to others could increase the risk of exposure to phishing attacks.

  • A. Correct.

    This is correct. Verifying directly with the IT department via an official channel is a key step in confirming whether the email is legitimate.

  • B. Incorrect.

    This is incorrect. Clicking on suspicious links can lead to malicious websites or compromise sensitive information.

  • C. Correct.

    This is correct. Examining the sender's email address for inconsistencies, such as misspelled domains or unfamiliar addresses, can help identify phishing attempts.

  • D. Incorrect.

    This is incorrect. Forwarding potentially malicious emails to colleagues could spread the phishing attempt further and is not a recommended security practice.

  • E. Correct.

    This is correct. Reporting the email to the IT or security team allows them to investigate the threat and take appropriate action.

Timed practice exam

Take a 100-140 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam