nerdexam
CompTIA

CV0-003 · Question #263

Several suspicious emails are being reported from end users. Organizational email is hosted by a SaaS provider. Upon investigation, the URL in the email links to a phishing site where users are…

The correct answer is C. Change the encryption key for the entire organization and lock out all users from using email until. When a phishing campaign has potentially harvested domain credentials from users, the most decisive protective action is to invalidate all active credentials and lock users out until they reset their passwords. Changing the organizational encryption key and locking accounts…

Security

Question

Several suspicious emails are being reported from end users. Organizational email is hosted by a SaaS provider. Upon investigation, the URL in the email links to a phishing site where users are prompted to enter their domain credentials to reset their passwords. Which of the following should the cloud administrator do to protect potential account compromise?

Options

  • AForward the email to the systems team distribution list and provide the compromised user list.
  • BClick on the URL link to verify the website and enter false domain credentials.
  • CChange the encryption key for the entire organization and lock out all users from using email until
  • DNotify users who received the email to reset their passwords regardless of whether they click on

How the community answered

(55 responses)
  • A
    2% (1)
  • B
    9% (5)
  • C
    84% (46)
  • D
    5% (3)

Explanation

When a phishing campaign has potentially harvested domain credentials from users, the most decisive protective action is to invalidate all active credentials and lock users out until they reset their passwords. Changing the organizational encryption key and locking accounts ensures that any stolen credentials become immediately unusable - even for users who already entered their credentials on the phishing site. Option A only escalates without taking protective action. Option B is dangerous; IT staff must never click phishing links or enter any credentials, even false ones, as doing so can trigger drive-by downloads or validate the link to attackers. Option D merely notifies users but relies on voluntary compliance rather than enforcing credential resets, leaving compromised accounts exposed until users act on their own.

Topics

#phishing#incident response#SaaS security#credential compromise

Community Discussion

No community discussion yet for this question.

Full CV0-003 Practice