nerdexam
CompTIA

220-1102 · Question #27

After clicking on a link in an email a Chief Financial Officer (CFO) received the following error: The CFO then reported the incident to a technician. The link is purportedly to the organization's…

The correct answer is D. Instruct the CFO to exit the browser. The scenario describes a likely phishing attack. The immediate priority is to contain the threat by instructing the CFO to exit the browser, stopping any further interaction with the potentially malicious site and halting any scripts or drive-by downloads. Safety and…

Security

Question

After clicking on a link in an email a Chief Financial Officer (CFO) received the following error:

The CFO then reported the incident to a technician. The link is purportedly to the organization's bank. Which of the following should the technician perform FIRST?

Exhibit

220-1102 question #27 exhibit

Options

  • AUpdate the browser's CRLs
  • BFile a trouble ticket with the bank.
  • CContact the ISP to report the CFCs concern
  • DInstruct the CFO to exit the browser

How the community answered

(62 responses)
  • A
    3% (2)
  • B
    5% (3)
  • C
    8% (5)
  • D
    84% (52)

Explanation

The scenario describes a likely phishing attack. The immediate priority is to contain the threat by instructing the CFO to exit the browser, stopping any further interaction with the potentially malicious site and halting any scripts or drive-by downloads. Safety and containment always come first. Updating CRLs (A) is a follow-up step. Filing a trouble ticket with the bank (B) and contacting the ISP (C) are secondary actions taken after the immediate risk is neutralized. 'First' in security contexts always means stop the bleeding.

Topics

#Incident Response#Phishing Attack#Containment#Browser Security

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice