FC0-U61 · Question #224
A user receives an email from the bank stating that the user needs to follow a link and re-enter login credentials due to recent security breaches. Based on best practices, which of the following acti
The correct answer is C. Delete the message. E. Contact the bank.. This email is a classic phishing attempt, and the best practices involve deleting the suspicious message and directly contacting the bank through official channels to verify any legitimate security concerns. Following links in such emails or replying to them is highly risky.
Question
A user receives an email from the bank stating that the user needs to follow a link and re-enter login credentials due to recent security breaches. Based on best practices, which of the following actions should the user take? (Select TWO).
Options
- AInform the ISP.
- BFollow the instructions.
- CDelete the message.
- DReply to the email.
- EContact the bank.
How the community answered
(46 responses)- A9% (4)
- B2% (1)
- C83% (38)
- D7% (3)
Why each option
This email is a classic phishing attempt, and the best practices involve deleting the suspicious message and directly contacting the bank through official channels to verify any legitimate security concerns. Following links in such emails or replying to them is highly risky.
Informing the ISP is generally not the immediate primary action for a phishing email from a bank; the focus should be on personal security and verifying with the bank.
Following the instructions (clicking a link and entering credentials) is precisely what the phisher wants and would lead to compromise of the user's account.
Deleting the message prevents accidental future interaction with the malicious email and removes a potential vector for attack from the user's inbox. Phishing emails should always be deleted to avoid falling victim to their traps.
Replying to the email confirms to the attacker that the email address is active and the user is susceptible to interaction, potentially leading to more targeted attacks.
Contacting the bank directly through an officially published phone number or website (not from the email) is crucial to verify if the security breach claim is legitimate and to inquire about actual steps required. This bypasses the phishing attempt and ensures interaction with the authentic institution.
Concept tested: Phishing email handling best practices
Source: https://www.microsoft.com/en-us/microsoft-365/blog/2014/11/06/learn-identify-avoid-phishing-scams/
Topics
Community Discussion
No community discussion yet for this question.