220-1102 Question 767
Single answerTexting/social media sitesA user brings a company-issued smartphone to the help desk after tapping a link in a direct message on a social media app. The message claimed the user's account would be suspended unless they "verify immediately." After entering their username and password on the linked page, the user noticed the page looked unusual and reported it. Which action should the technician recommend FIRST to reduce the risk of account compromise?
- A
Change the social media account password immediately and enable MFA if it is not already enabled
- B
Clear the phone's browser cache and cookies to remove the phishing page
- C
Uninstall and reinstall the social media app to remove any malicious messages
- D
Factory reset the smartphone before taking any other action
Show answer and explanation
Correct answer: A
Explanation
This question focuses on social engineering through texting/social media platforms, a common A+ Core 2 security topic. In a realistic support scenario, the technician should prioritize limiting damage from suspected credential theft. Best practice is to change the affected password immediately, review account activity, and enable MFA where available. If the same password was reused elsewhere, those accounts should also be updated. The user should also be advised to report the phishing message through the platform's reporting tools and avoid interacting with similar urgent or threatening messages in the future. This aligns with general security guidance from major vendors and cybersecurity best practices: after suspected phishing, secure the account first, then investigate device impact as needed.
- A. Correct.
Correct. If the user entered credentials into a likely phishing page, the most urgent step is to prevent unauthorized access by changing the password right away. Enabling multi-factor authentication adds another layer of protection in case the password has already been captured. This is consistent with standard security response practices for suspected credential compromise.
- B. Incorrect.
Incorrect. Clearing cache and cookies may remove stored browser data, but it does not protect an account if the user already submitted credentials to an attacker-controlled site. This option addresses local browser data rather than the immediate risk of account takeover.
- C. Incorrect.
Incorrect. Reinstalling the app does not invalidate stolen credentials and is not the first priority in a phishing situation. The message itself may have been malicious, but the greater risk is that the attacker now has the user's username and password.
- D. Incorrect.
Incorrect. A factory reset is excessive as a first step in this scenario. The main issue described is credential theft through social engineering, not confirmed malware infection on the device. Resetting the device would be disruptive and would not by itself secure the compromised account.