220-1002 · Question #667
A user opens a phishing email and types logon credentials into a fake banking website. The computer's antivirus software then reports it has several from the network. Which of the following should…
The correct answer is A. Have the user change the password. After credentials are entered into a phishing site, changing the compromised password is the most urgent next step because attackers can immediately use stolen credentials from any location.
Question
A user opens a phishing email and types logon credentials into a fake banking website. The computer's antivirus software then reports it has several from the network. Which of the following should the technician perform NEXT?
Options
- AHave the user change the password.
- BUpdate the antivirus software and run scans.
- CDisable the user's local computer account.
- DQuarantine the phishing email.
How the community answered
(34 responses)- A71% (24)
- B3% (1)
- C9% (3)
- D18% (6)
Why each option
After credentials are entered into a phishing site, changing the compromised password is the most urgent next step because attackers can immediately use stolen credentials from any location.
Changing the password immediately is the highest-priority action because the attacker now possesses valid credentials that can be used to access the real banking account from any external system, regardless of whether the local machine is cleaned. Every minute the old password remains valid increases the window for financial harm. Malware remediation is important but secondary to revoking the attacker's access.
Updating antivirus and running scans addresses local malware but does not invalidate the stolen credentials, which the attacker can use from their own system entirely outside the victim network.
Disabling the local computer account prevents local logon but has no effect on external accounts such as online banking whose credentials were submitted to the phishing site.
Quarantining the phishing email prevents future interaction with it but does not help because the credentials have already been submitted and received by the attacker.
Concept tested: Incident response priority after credential phishing
Source: https://learn.microsoft.com/en-us/security/compass/incident-response-overview
Topics
Community Discussion
No community discussion yet for this question.