SK0-005 · Question #363
A user has been unable to authenticate to the company's external, web-based database after clicking a link in an email that required the user to change the account password. Which of the following ste
The correct answer is A. Disable the user's account and inform the security team.. This scenario describes a phishing attack. The user clicked a malicious link that likely directed them to a fake password-change page, harvesting their credentials. The company should immediately disable the account to prevent unauthorized access and escalate to the security team
Question
A user has been unable to authenticate to the company's external, web-based database after clicking a link in an email that required the user to change the account password. Which of the following steps should the company take next?
Options
- ADisable the user's account and inform the security team.
- BCreate a new log-in to the external database.
- CAsk the user to use the link again to reset the password.
- DReset the user's password and ask the user to log in again.
How the community answered
(21 responses)- A71% (15)
- B5% (1)
- C10% (2)
- D14% (3)
Explanation
This scenario describes a phishing attack. The user clicked a malicious link that likely directed them to a fake password-change page, harvesting their credentials. The company should immediately disable the account to prevent unauthorized access and escalate to the security team for investigation. Asking the user to click the link again or simply resetting the password without investigation would expose the user to further compromise. Creating a new login does not address the security incident and the attacker may already have the original credentials.
Topics
Community Discussion
No community discussion yet for this question.