nerdexam
CompTIA

220-1102 · Question #853

An employee of Company X receives an email from [email protected] that appears to be from the local IT administrator. This email states that the employee's computer has been infected with a…

The correct answer is B. Contact the IT department to ask for additional direction. The employee should verify the legitimacy of a suspicious email that claims to be from IT by contacting the IT department through a known, independent channel. This prevents potential malware infection or credential compromise from a phishing attempt.

Security

Question

An employee of Company X receives an email from [email protected] that appears to be from the local IT administrator. This email states that the employee's computer has been infected with a virus and an included link must be clicked to remove the virus. Which of the following actions should the employee take next?

Options

  • AClick the link and follow all included directions to remove the virus.
  • BContact the IT department to ask for additional direction.
  • CForward the email to all users who the employee has shared files with.
  • DDelete the email and disregard any requested action.
  • EReply to the email to ask for confirmation that the email is legitimate.

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    73% (16)
  • D
    14% (3)
  • E
    5% (1)

Why each option

The employee should verify the legitimacy of a suspicious email that claims to be from IT by contacting the IT department through a known, independent channel. This prevents potential malware infection or credential compromise from a phishing attempt.

AClick the link and follow all included directions to remove the virus.

Clicking the link in a suspicious email is dangerous as it could lead to malware infection, a drive-by download, or a phishing site designed to steal credentials.

BContact the IT department to ask for additional direction.Correct

Contacting the IT department directly via a verified phone number or internal ticketing system allows the employee to confirm if the email is legitimate before taking any action. This is the safest way to handle potential phishing attempts and enables IT to investigate and warn other employees.

CForward the email to all users who the employee has shared files with.

Forwarding a potentially malicious email to others could inadvertently spread a phishing attempt or malware to more users.

DDelete the email and disregard any requested action.

While deleting the email might prevent accidental clicks, it prevents the IT department from being able to investigate the phishing attempt and take broader protective measures.

EReply to the email to ask for confirmation that the email is legitimate.

Replying to a suspicious email directly might confirm to the attacker that the email address is active, potentially leading to more targeted attacks.

Concept tested: Phishing recognition and reporting

Source: https://www.microsoft.com/en-us/security/business/security-awareness/phishing-scams

Topics

#Phishing#Social Engineering#Security Awareness#Incident Reporting

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice