nerdexam
CompTIA

CV0-002 · Question #263

Several suspicious emails are being reported from end users. Organizational email is hosted by a SaaS provider. Upon investigation, the URL in the email links to a phishing site where users are prompt

The correct answer is C. Change the encryption key for the entire organization and lock out all users from using email until. To protect against potential account compromise from phishing for domain credentials, a drastic immediate containment strategy is to change organizational encryption keys and lock out email access for all users.

Security

Question

Several suspicious emails are being reported from end users. Organizational email is hosted by a SaaS provider. Upon investigation, the URL in the email links to a phishing site where users are prompted to enter their domain credentials to reset their passwords. Which of the following should the cloud administrator do to protect potential account compromise?

Options

  • AForward the email to the systems team distribution list and provide the compromised user list.
  • BClick on the URL link to verify the website and enter false domain credentials.
  • CChange the encryption key for the entire organization and lock out all users from using email until
  • DNotify users who received the email to reset their passwords regardless of whether they click on

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    12% (5)
  • C
    55% (23)
  • D
    26% (11)

Why each option

To protect against potential account compromise from phishing for domain credentials, a drastic immediate containment strategy is to change organizational encryption keys and lock out email access for all users.

AForward the email to the systems team distribution list and provide the compromised user list.

Forwarding emails and providing lists is an information-sharing step, but it does not proactively protect compromised accounts or prevent further malicious activity.

BClick on the URL link to verify the website and enter false domain credentials.

Clicking on a malicious URL, even to enter false credentials, is dangerous and could expose the administrator's system to malware or further compromise, and is not a protective measure.

CChange the encryption key for the entire organization and lock out all users from using email untilCorrect

If user domain credentials have been compromised through a phishing attack, there's a risk these credentials could be used to access or derive sensitive organizational keys. Changing the organization's encryption key and locking out email access acts as a comprehensive immediate containment strategy, preventing further unauthorized access to critical systems or data until the extent of the compromise is fully assessed and remediated.

DNotify users who received the email to reset their passwords regardless of whether they click on

Notifying users to reset passwords is a crucial step, but it is reactive to individual user actions and might not be immediate enough or sufficiently comprehensive to address potential broader system-wide risks if the phished credentials could be leveraged for greater access, which answer C implies by its drastic nature.

Concept tested: Incident response for credential compromise (phishing)

Topics

#phishing#account compromise#incident response#SaaS security

Community Discussion

No community discussion yet for this question.

Full CV0-002 Practice