nerdexam
CompTIA

CS0-003 · Question #107

While monitoring the information security notification mailbox, a security analyst notices several emails were reported as spam. Which of the following should the analyst do FIRST?

The correct answer is D. Review the message in a secure environment.. When multiple emails are reported as spam, a security analyst should first review the messages in a secure, isolated environment.

Submitted by tyler.j· Mar 6, 2026Incident Response and Management

Question

While monitoring the information security notification mailbox, a security analyst notices several emails were reported as spam. Which of the following should the analyst do FIRST?

Options

  • ABlock the sender In the email gateway.
  • BDelete the email from the company's email servers.
  • CAsk the sender to stop sending messages.
  • DReview the message in a secure environment.

How the community answered

(19 responses)
  • A
    11% (2)
  • B
    5% (1)
  • C
    5% (1)
  • D
    79% (15)

Why each option

When multiple emails are reported as spam, a security analyst should first review the messages in a secure, isolated environment.

ABlock the sender In the email gateway.

Blocking the sender immediately without review could lead to blocking legitimate emails (false positive) or might not address sophisticated threats like spoofing.

BDelete the email from the company's email servers.

Deleting the email from servers prematurely could remove critical evidence necessary for further investigation if the message turns out to be malicious.

CAsk the sender to stop sending messages.

Asking the sender to stop sending messages is ineffective if the sender is malicious or compromised, and it does not address the immediate threat assessment.

DReview the message in a secure environment.Correct

Reviewing the message in a secure environment, such as a sandbox or isolated virtual machine, is the critical first step to safely assess if the reported spam is benign, a phishing attempt, or contains malware, without risking compromise to the production network.

Concept tested: Email security triage

Source: https://www.sans.org/blog/how-to-do-email-forensics-and-triage/

Topics

#Email security#Phishing analysis#Incident triage#Secure sandbox

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice