220-1102 Question 431
Single answerVishingA help desk technician receives a phone call from someone claiming to be the company's bank fraud department. The caller says there have been suspicious wire transfers and instructs the technician to immediately provide the CFO's mobile number and the one-time verification code that was just sent to the CFO's phone so the account can be secured. The caller sounds professional, knows the company name, and insists the matter is urgent. What is the BEST action for the technician to take?
- A
Provide the CFO's mobile number and ask the caller to wait while you contact the CFO for the verification code
- B
Refuse to share the information, end the call, and report the incident through the organization's security or incident reporting process
- C
Ask the caller to verify the last four digits of the bank account before sharing the requested information
- D
Transfer the caller directly to the CFO because the issue involves a possible financial crime
Show answer and explanation
Correct answer: B
Explanation
This scenario describes vishing, a form of social engineering conducted by phone. Common indicators include urgency, authority, and requests for sensitive information such as contact details, authentication codes, or account access data. In A+ Core 2 security best practices, users and technicians should be trained to recognize social engineering attempts, avoid disclosing information during unsolicited communications, and report suspected incidents according to organizational policy. Verification should be performed by independently contacting the institution using a trusted phone number from official records or the organization's approved procedures, not by relying on caller-provided information. One-time passcodes and multifactor authentication codes should never be shared with unexpected callers.
- A. Incorrect.
Incorrect. This would disclose sensitive contact information and facilitate account compromise. One-time verification codes are intended to confirm identity for the legitimate account holder and should not be shared with unsolicited callers. This option reflects a common mistake of trying to be helpful during a social engineering attack.
- B. Correct.
Correct. This is the appropriate response to a suspected vishing attempt. Vishing is voice-based phishing in which an attacker uses a phone call to create urgency and obtain sensitive information. The technician should not disclose data, should terminate the unsolicited call, and should follow company procedures for reporting a potential social engineering incident.
- C. Incorrect.
Incorrect. Asking the caller for partial account details does not sufficiently validate identity and may create a false sense of trust. Attackers often possess some real information from prior breaches, public sources, or reconnaissance. The safer practice is to avoid sharing information during an unsolicited call and use official contact methods if verification is needed.
- D. Incorrect.
Incorrect. Transferring the caller to an executive escalates the risk and bypasses verification procedures. Attackers commonly target high-value personnel such as executives using urgency and authority. The technician should follow established incident handling procedures rather than forwarding the call.