nerdexam
CompTIA

SY0-501 · Question #110

Security administrators attempted corrective action after a phishing attack. Users are still experiencing trouble logging in, as well as an increase in account lockouts. Users' email contacts are comp

Sign in or unlock SY0-501 to reveal the answer and full explanation for question #110. The question stem and answer options stay visible for context.

Submitted by ravi_2018· Mar 4, 2026Security operations

Question

Security administrators attempted corrective action after a phishing attack. Users are still experiencing trouble logging in, as well as an increase in account lockouts. Users' email contacts are complaining of an increase in spam and social networking requests. Due to the large number of affected accounts, remediation must be accomplished quickly. Which of the following actions should be taken FIRST? (Select TWO)

Options

  • ADisable the compromised accounts
  • BUpdate WAF rules to block social networks
  • CRemove the compromised accounts with all AD groups
  • DChange the compromised accounts' passwords
  • EDisable the open relay on the email server
  • FEnable sender policy framework

Unlock SY0-501 to see the answer

You've previewed enough free SY0-501 questions. Unlock SY0-501 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#phishing remediation#email security#SPF#open relay
Full SY0-501 Practice