nerdexam
CompTIA

SY0-701 · Question #533

An employee emailed a new systems administrator a malicious web link and convinced the administrator to change the email server's password. The employee used this access to remove the mailboxes of…

The correct answer is A. Recognizing phishing. Phishing recognition is the correct answer because the attack described - sending a malicious link via email to manipulate someone into handing over credentials - is the textbook definition of a phishing attack. Training employees to identify suspicious links, verify sender…

Submitted by yuriko_h· Mar 6, 2026Threats, vulnerabilities, and mitigations

Question

An employee emailed a new systems administrator a malicious web link and convinced the administrator to change the email server's password. The employee used this access to remove the mailboxes of key personnel. Which of the following security awareness concepts would help prevent this threat in the future?

Options

  • ARecognizing phishing
  • BProviding situational awareness training
  • CUsing password management
  • DReviewing email policies

How the community answered

(27 responses)
  • A
    93% (25)
  • B
    4% (1)
  • D
    4% (1)

Explanation

Phishing recognition is the correct answer because the attack described - sending a malicious link via email to manipulate someone into handing over credentials - is the textbook definition of a phishing attack. Training employees to identify suspicious links, verify sender identities, and question unusual requests would directly prevent this specific social engineering technique.

  • B (Situational awareness) is too broad; it covers general environmental threats and anomaly detection, not specifically email-based credential manipulation.
  • C (Password management) addresses how passwords are stored and complexity requirements, but the problem here is that the admin was socially engineered into changing the password willingly - not that the password was weak or poorly managed.
  • D (Reviewing email policies) might be a downstream control, but policies alone don't prevent an employee from being deceived if they can't recognize the attack in the first place.

Memory tip: If the attack starts with a suspicious email link that tricks someone into acting, think phishing - the hook is always the email lure.

Topics

#Phishing#Social Engineering#Security Awareness

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice