220-1102 Question 430
Single answerPhishingA user reports receiving an email that appears to be from the company's payroll provider, stating their direct-deposit information must be updated immediately to avoid delayed pay. The email includes a link to a login page that looks legitimate, but the sender's address is slightly misspelled and the page URL does not match the real payroll provider's domain. The user already clicked the link but did not enter any credentials. What should the technician advise the user to do FIRST?
- A
Forward the email to coworkers so they know what to avoid, then delete it
- B
Close the browser tab, report the message as phishing according to company procedure, and avoid interacting with the site further
- C
Reply to the sender asking whether the email is legitimate before taking any other action
- D
Enter fake credentials to confirm whether the site is collecting passwords
Show answer and explanation
Correct answer: B
Explanation
The best first action is to stop interacting with the suspected phishing site and report the incident through the organization's established process. In this scenario, the warning signs include urgency, a slightly misspelled sender address, and a mismatched URL, all of which are common phishing indicators. Because no credentials were entered, containment focuses on preventing further interaction and enabling security staff to investigate whether additional remediation is needed, such as checking browser history, reviewing endpoint protection alerts, or blocking the sender/domain. This approach is consistent with common security awareness best practices promoted by organizations such as CISA and NIST: verify requests through trusted channels, do not engage with suspicious messages, and report phishing attempts promptly.
- A. Incorrect.
This is incorrect. Although warning others may seem helpful, forwarding a suspected phishing email can spread the malicious message and increase risk. The better practice is to use the organization's reporting process, such as a phishing-report button, security mailbox, or help desk ticket. Deleting it without proper reporting may also prevent security staff from investigating the campaign.
- B. Correct.
This is correct. Since the user clicked the link but did not submit credentials, the immediate priority is to stop further interaction, close the page, and report the phishing attempt through established company procedures. This aligns with standard security awareness guidance: do not click further, do not download anything, and escalate suspected phishing so IT or security can investigate and block similar messages.
- C. Incorrect.
This is incorrect. Replying confirms the email address is active and engages the attacker. Phishing messages often use spoofed or throwaway addresses, so a reply does not validate legitimacy. Best practice is to avoid interacting with the sender and instead verify any payroll-related request through a trusted channel, such as the known payroll portal or official HR contact information.
- D. Incorrect.
This is incorrect. Entering fake credentials is unsafe and unprofessional. Some phishing sites log all submissions, use entered usernames for later attacks, or trigger malicious scripts. A technician should never test a suspicious site this way. Investigation should be handled by authorized security personnel using approved tools and procedures.