100-140 · Question #38
You receive an email request for personal information. You need to make sure you are working with the right individual to avoid a social engineering attempt. Which step should you take?
The correct answer is C. Use company approved methods to confirm the individual's identity.. The safest and most professional approach is to use company-approved methods to verify identity, such as callback procedures, employee ID verification, or multi-factor authentication. This helps prevent falling victim to phishing or social engineering.
Question
Options
- ARespond to the email request from the individual to ask them for personal information.
- BAllow the individual to volunteer to share identity information.
- CUse company approved methods to confirm the individual's identity.
- DShare personal account information and ask the individual to confirm it.
How the community answered
(32 responses)- A3% (1)
- B9% (3)
- C75% (24)
- D13% (4)
Explanation
The safest and most professional approach is to use company-approved methods to verify identity, such as callback procedures, employee ID verification, or multi-factor authentication. This helps prevent falling victim to phishing or social engineering.
Topics
Community Discussion
6C is your answer, and it matters why the others fall flat. Responding to the email itself (A) or letting someone volunteer their own identity details (B) hands control to whoever is on the other end, which is exactly what a social engineer is counting on. Sharing account data and asking them to confirm it (D) is even worse because you have just handed over information that could be used against you or the account holder. Company approved verification methods exist for this exact scenario, whether that is a callback to a number on file, a ticket through your internal system, or a supervisor escalation, so use them and document that you did.
Solid breakdown, and the documentation piece you dropped at the end is worth underlining because exams will sometimes frame a follow-up question around what happens after verification, and candidates who treat documentation as optional in practice tend to miss those questions on test day.
C is the only answer that closes the loop without creating a new attack surface. A and D both involve you either responding to or confirming data through a channel the attacker already controls, which is exactly how pretexting works. B sounds polite but it hands control to the requester, and a skilled social engineer will absolutely volunteer just enough true detail to seem legitimate. The core rule for any card worth making here is this: always verify identity through an out-of-band, company-approved method before you touch any personal data, full stop. On my actual exam I flagged this one and came back to it because D felt like a trap set specifically for people who know "never give out info" but misread the answer as "just confirm, don't share." When I read D again carefully I realized you are still exposing account data to an unverified party, which fails the same way A does. Landed on C with about 30 seconds left on that section and never looked back.
D is the obvious trap since reading back account info over an unverified channel is exactly what phishing exploits, and B sounds almost reasonable until you realize letting someone self-identify proves nothing. C is right because your company's identity verification procedures exist specifically for this scenario, whether that is calling back on a number of record or routing through an authenticated portal.
Someone volunteering freely is harder to fake than any scripted response.
Grace, I get where you're coming from, but C is actually the stronger pick here because voluntary behavior can still be coached or rehearsed, whereas the option in C points to something more structural that is harder to manipulate regardless of motivation.