220-1102 Question 307
Single answerInstant messagingA small accounting firm uses a company-approved instant messaging platform for internal communication and to send quick updates to clients. An employee reports receiving a direct message from someone claiming to be the firm's managing partner, asking for employee tax documents to be uploaded immediately through a link in the chat. The display name matches the partner, but the username is slightly different, and the message creates urgency. What is the BEST action for the technician to recommend?
- A
Tell the employee to upload the files because the display name matches the managing partner
- B
Have the employee reply in the chat and ask the sender to confirm their password as proof of identity
- C
Advise the employee not to click the link, verify the request through a trusted separate channel, and report the message as suspicious
- D
Instruct the employee to forward the message to all staff so others can decide whether it is legitimate
Show answer and explanation
Correct answer: C
Explanation
This question tests recognition of instant messaging-based phishing, sometimes called smishing or business messaging impersonation depending on the platform and context. In A+ Core 2, users are expected to identify social engineering attempts and respond appropriately. Key warning signs here are impersonation, urgency, a request for sensitive information, and a mismatched username. The best response follows standard security practice: do not click unexpected links, do not provide sensitive data through chat without validation, verify requests through an independent trusted channel, and report the incident. These actions align with common organizational security awareness guidance and general best practices published by security authorities such as CISA and NIST on phishing awareness, identity verification, and safe handling of suspicious communications.
- A. Incorrect.
This is incorrect. Matching display names are not a reliable way to verify identity in an instant messaging platform. Attackers commonly spoof names or create lookalike accounts. Uploading sensitive tax documents based only on a display name would violate basic security best practices around identity verification and data handling.
- B. Incorrect.
This is incorrect. Asking for or sharing passwords is not an appropriate way to verify identity. Passwords should never be requested or disclosed through instant messaging. This option reflects a common security misconception and would create an additional credential-compromise risk.
- C. Correct.
This is correct. The message shows several phishing and social engineering indicators: urgency, a sensitive data request, a suspicious link, and a slightly different username. Best practice is to avoid interacting with the link, confirm the request using a known trusted method such as a phone call or verified email address, and report the message to the organization's security contact or through the platform's reporting feature.
- D. Incorrect.
This is incorrect. Forwarding a suspicious message to all staff can increase confusion, spread malicious links, and expose more users to the attack. The proper response is containment and reporting, not wider distribution.