nerdexam
CompTIA

220-1102 · Question #487

A user clicks a link in an email. A warning message in the user's browser states the site's certificate cannot be verified. Which of the following is the most appropriate action for a technician to…

The correct answer is D. Close the browser window and report the email to IT security. Upon encountering a browser warning about an unverified certificate after clicking an email link, the user should immediately close the browser and report the suspicious email to IT security.

Security

Question

A user clicks a link in an email. A warning message in the user's browser states the site's certificate cannot be verified. Which of the following is the most appropriate action for a technician to take?

Options

  • AClick proceed.
  • BReport the employee to the human resources department for violating company policy.
  • CRestore the computer from the last known backup.
  • DClose the browser window and report the email to IT security.

How the community answered

(40 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    13% (5)
  • D
    78% (31)

Why each option

Upon encountering a browser warning about an unverified certificate after clicking an email link, the user should immediately close the browser and report the suspicious email to IT security.

AClick proceed.

Clicking "proceed" ignores the security warning and could lead to compromise, data theft, or malware infection.

BReport the employee to the human resources department for violating company policy.

While clicking a suspicious link might violate policy, the immediate priority is to contain the potential security threat, not punitive action against the employee.

CRestore the computer from the last known backup.

Restoring the computer from backup is an extreme measure usually taken after a confirmed infection, not merely a browser warning, and doesn't address the suspicious email itself.

DClose the browser window and report the email to IT security.Correct

Closing the browser window and reporting the email to IT security is the most appropriate action because an unverified certificate often indicates a potentially malicious or compromised website (e.g., a phishing site or man-in-the-middle attack). Reporting allows IT security to investigate the email's origin and potentially block it for other users, preventing further risk.

Concept tested: Incident response for suspicious browser warnings

Topics

#Security awareness#Phishing#Digital certificates#Incident response

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice