220-1002 · Question #174
Joe, a user, reports that several of his colleagues have received a suspicious email from his account that he did not send. A technician asks one of the colleagues to forward the email for…
The correct answer is D. Isolate Joe's computer from the network. Since spoofing has been ruled out and the email genuinely originated from the corporate server, Joe's account or computer has likely been compromised - possibly by malware that is actively sending emails. The immediate priority is to isolate Joe's computer from the network to…
Question
Joe, a user, reports that several of his colleagues have received a suspicious email from his account that he did not send. A technician asks one of the colleagues to forward the email for inspection. After ruling out spoofing, the technician verifies the email originated from the corporate email server. Which of the following is the FIRST step the technician should take to correct this issue?
Options
- ASee if Joe's email address has been blacklisted
- BChange the password on Joe's email account
- CUpdate the antivirus and perform a full scan on the PC
- DIsolate Joe's computer from the network
How the community answered
(31 responses)- A6% (2)
- B3% (1)
- C6% (2)
- D84% (26)
Explanation
Since spoofing has been ruled out and the email genuinely originated from the corporate server, Joe's account or computer has likely been compromised - possibly by malware that is actively sending emails. The immediate priority is to isolate Joe's computer from the network to stop any ongoing malicious activity and prevent further spread or data exfiltration. This is the containment step. Changing the password and running antivirus scans are important subsequent steps, but isolation must come first to limit damage. Blacklisting Joe's email address would disrupt legitimate business operations and is not the appropriate first response.
Topics
Community Discussion
No community discussion yet for this question.