220-1002 · Question #601
A user is trying to access a popular email website but Is being redirected to a different website that asks for login credentials. The user calls a technician, who promptly notices a security issue…
The correct answer is B. Remove all files from the temporary folder and restart the computer. A user being redirected to a credential-harvesting site indicates malicious cached browser data, and clearing the temporary folder then restarting removes the threat causing the redirect.
Question
A user is trying to access a popular email website but Is being redirected to a different website that asks for login credentials. The user calls a technician, who promptly notices a security issue. Which of the following should the technician do to remove the threat from the system?
Options
- ARemove all parameters after the FQDN website address
- BRemove all files from the temporary folder and restart the computer.
- CRemove and reinstall the web browser In safe mode.
- DRemove all lines that are not comments from the hosts file
How the community answered
(50 responses)- A8% (4)
- B76% (38)
- C14% (7)
- D2% (1)
Why each option
A user being redirected to a credential-harvesting site indicates malicious cached browser data, and clearing the temporary folder then restarting removes the threat causing the redirect.
Removing URL parameters from the address bar does not address any underlying malicious files or system configuration changes causing the redirect.
Malicious files or scripts stored in the browser's temporary folder can persistently redirect users to phishing sites designed to steal credentials. Deleting all files from the temporary folder removes the cached malicious content, and restarting the computer terminates any active processes that were leveraging it to perform the redirect, restoring normal browsing behavior.
Reinstalling the browser in safe mode is more involved than necessary and does not guarantee removal of malicious files that persist in the temporary folder outside the browser's installation directory.
Clearing non-comment lines from the hosts file would remediate a hosts-file-based DNS redirect but does not address browser-cached malicious content stored in temporary files.
Concept tested: Removing browser redirect malware via temporary file cleanup
Source: https://support.microsoft.com/en-us/windows/delete-temporary-files-in-windows-a082b9b8-1c32-48b7-a9e0-9a4c52a3d7b6
Topics
Community Discussion
No community discussion yet for this question.