nerdexam
CompTIA

FC0-U61 · Question #224

A user receives an email from the bank stating that the user needs to follow a link and re-enter login credentials due to recent security breaches. Based on best practices, which of the following acti

The correct answer is C. Delete the message. E. Contact the bank.. This email is a classic phishing attempt, and the best practices involve deleting the suspicious message and directly contacting the bank through official channels to verify any legitimate security concerns. Following links in such emails or replying to them is highly risky.

Security

Question

A user receives an email from the bank stating that the user needs to follow a link and re-enter login credentials due to recent security breaches. Based on best practices, which of the following actions should the user take? (Select TWO).

Options

  • AInform the ISP.
  • BFollow the instructions.
  • CDelete the message.
  • DReply to the email.
  • EContact the bank.

How the community answered

(46 responses)
  • A
    9% (4)
  • B
    2% (1)
  • C
    83% (38)
  • D
    7% (3)

Why each option

This email is a classic phishing attempt, and the best practices involve deleting the suspicious message and directly contacting the bank through official channels to verify any legitimate security concerns. Following links in such emails or replying to them is highly risky.

AInform the ISP.

Informing the ISP is generally not the immediate primary action for a phishing email from a bank; the focus should be on personal security and verifying with the bank.

BFollow the instructions.

Following the instructions (clicking a link and entering credentials) is precisely what the phisher wants and would lead to compromise of the user's account.

CDelete the message.Correct

Deleting the message prevents accidental future interaction with the malicious email and removes a potential vector for attack from the user's inbox. Phishing emails should always be deleted to avoid falling victim to their traps.

DReply to the email.

Replying to the email confirms to the attacker that the email address is active and the user is susceptible to interaction, potentially leading to more targeted attacks.

EContact the bank.Correct

Contacting the bank directly through an officially published phone number or website (not from the email) is crucial to verify if the security breach claim is legitimate and to inquire about actual steps required. This bypasses the phishing attempt and ensures interaction with the authentic institution.

Concept tested: Phishing email handling best practices

Source: https://www.microsoft.com/en-us/microsoft-365/blog/2014/11/06/learn-identify-avoid-phishing-scams/

Topics

#phishing#email security#security awareness#best practices

Community Discussion

No community discussion yet for this question.

Full FC0-U61 Practice