220-1102 · Question #487
A user clicks a link in an email. A warning message in the user's browser states the site's certificate cannot be verified. Which of the following is the most appropriate action for a technician to…
The correct answer is D. Close the browser window and report the email to IT security. Upon encountering a browser warning about an unverified certificate after clicking an email link, the user should immediately close the browser and report the suspicious email to IT security.
Question
A user clicks a link in an email. A warning message in the user's browser states the site's certificate cannot be verified. Which of the following is the most appropriate action for a technician to take?
Options
- AClick proceed.
- BReport the employee to the human resources department for violating company policy.
- CRestore the computer from the last known backup.
- DClose the browser window and report the email to IT security.
How the community answered
(40 responses)- A8% (3)
- B3% (1)
- C13% (5)
- D78% (31)
Why each option
Upon encountering a browser warning about an unverified certificate after clicking an email link, the user should immediately close the browser and report the suspicious email to IT security.
Clicking "proceed" ignores the security warning and could lead to compromise, data theft, or malware infection.
While clicking a suspicious link might violate policy, the immediate priority is to contain the potential security threat, not punitive action against the employee.
Restoring the computer from backup is an extreme measure usually taken after a confirmed infection, not merely a browser warning, and doesn't address the suspicious email itself.
Closing the browser window and reporting the email to IT security is the most appropriate action because an unverified certificate often indicates a potentially malicious or compromised website (e.g., a phishing site or man-in-the-middle attack). Reporting allows IT security to investigate the email's origin and potentially block it for other users, preventing further risk.
Concept tested: Incident response for suspicious browser warnings
Topics
Community Discussion
No community discussion yet for this question.