312-39 · Question #31
The SOC team is investigating a phishing attack that targeted multiple employees. During the they opened it, clicked links, downloaded attachments, or entered credentials. This information is…
The correct answer is C. User action verification. User action verification is the activity that directly answers “what did users do with the phishing message?” In SOC containment, you need to rapidly determine exposure: who opened the email, who clicked the URL, who opened an attachment, and who submitted credentials. This…
Question
The SOC team is investigating a phishing attack that targeted multiple employees. During the they opened it, clicked links, downloaded attachments, or entered credentials. This information is critical to assessing impact and preventing further compromise. Which specific activity helps the SOC team understand user interactions with the phishing email?
Options
- AMonitoring and containment validation
- BMalware infection check
- CUser action verification
- DBlocking command-and-control (C2) and email traffic
How the community answered
(32 responses)- A6% (2)
- B3% (1)
- C88% (28)
- D3% (1)
Explanation
User action verification is the activity that directly answers “what did users do with the phishing message?” In SOC containment, you need to rapidly determine exposure: who opened the email, who clicked the URL, who opened an attachment, and who submitted credentials. This drives priority actions such as password resets, session revocation, MFA re-registration, endpoint isolation, URL/domain blocking, mailbox searches for similar messages, and targeted user notifications. Monitoring/containment validation confirms whether containment actions are effective (e.g., blocks are working, incidents aren’t spreading), but it does not specifically measure user interaction steps. Malware infection checks assess whether an endpoint is infected-useful if an attachment executed-but it comes after confirming interaction and is not the primary method to understand email engagement. Blocking C2 and email traffic is an active containment control, but it doesn’t provide the “who clicked/opened” understanding needed to scope impacted users. SOC analysts typically use email gateway telemetry, message trace, safe links/safe attachments logs, and identity sign-in logs to verify user actions. Because the question is explicitly about understanding user interactions, “User action verification” is the best match.
Topics
Community Discussion
No community discussion yet for this question.