Courseiva
Security →mediumMultiple Choice

FC0-U71 Security Practice Question

A help desk technician receives a call from someone claiming to be a company vice president who is traveling and urgently needs their password reset over the phone. The caller's number matches an internal extension. Which action should the technician take FIRST?

⚠ Common exam trap

The trap here is letting the claimed executive title and urgency override identity verification, when caller ID and pressure are exactly what pretexting relies on.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the caller's identity using the organization's established out-of-band procedure.

Urgency and a spoofable phone number are classic pretexting indicators. The technician should first confirm the caller's identity through the organization's out-of-band verification procedure, such as calling back a number from the directory or using a shared challenge. Only after verification should any password reset occur, which protects high-value accounts while still serving legitimate users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Provide a temporary password that expires in one hour and end the call.

    Why it's wrong here

    Issuing even a short-lived password still grants access to whoever is on the line, and the identity remains unverified. An attacker could log in during that window and establish persistence. Expiration limits exposure but does not replace the need to confirm the requester before making any credential change.

  • ✓

    Verify the caller's identity using the organization's established out-of-band procedure.

    Why this is correct

    Following the documented verification process, such as calling back a known number or using a shared challenge, confirms the request is genuine before any account change. This counters pretexting and caller ID spoofing while still allowing legitimate urgent requests to be handled. Verification first is the correct sequence for any sensitive account action.

  • ✗

    Reset the password immediately to avoid delaying the executive.

    Why it's wrong here

    Acting on urgency alone is exactly what social engineering exploits. The caller's identity has not been verified beyond a spoofable phone number, so resetting the password could hand an attacker access to a high-value account. Speed should never replace verification, regardless of the claimed title or urgency.

  • ✗

    Ask the caller to email the request from their company address instead.

    Why it's wrong here

    A company email address can be spoofed or an account may already be compromised, so receiving the request by email does not prove the caller's identity. This step also fails to follow a reliable verification standard and may simply move the social engineering attempt to another channel. It does not adequately confirm the person before a password reset.

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.