100-140 Question 359
Select 2An employee at your organization receives an email from what appears to be the IT department, requesting their login credentials to fix an urgent system issue. The email contains the organization’s logo but has a slightly misspelled sender address (e.g., 'it-support@compny.com' instead of 'it-support@company.com'). What steps should the employee take to handle this situation?
- A
Report the email to the IT security team and avoid clicking on any links or responding.
- B
Verify the sender’s email address carefully and look for unusual signs such as misspellings or incorrect domains.
- C
Click the link in the email to check if it leads to the legitimate company portal.
- D
Reply to the email requesting more details to confirm its authenticity.
- E
Delete the email immediately to prevent anyone else from interacting with it.
Show answer and explanation
Correct answers: A, B
Explanation
Phishing emails often include subtle signs of impersonation, such as misspelled sender addresses or urgent requests for sensitive information. Employees should verify the sender's details and report suspicious emails to the IT security team. This ensures that appropriate measures can be taken to protect the organization, such as alerting other users or blocking the sender. Interacting with the email, either by clicking links or replying, can lead to compromised credentials or further attacks.
- A. Correct.
Correct. Reporting the email ensures the IT security team can investigate and take preventive action. Avoiding interaction with the email prevents falling victim to the phishing attempt.
- B. Correct.
Correct. Verifying the sender’s email address and looking for signs of impersonation (e.g., misspellings) is an essential step to identify phishing attempts.
- C. Incorrect.
Incorrect. Clicking on suspicious links can lead to malicious websites or malware infections, which compromises security.
- D. Incorrect.
Incorrect. Responding to the email can provide the attacker with additional information or confirm that the email address is active, potentially escalating the attack.
- E. Incorrect.
Incorrect. While deleting the email removes it from the inbox, it bypasses the opportunity to alert the IT team, leaving others in the organization vulnerable.