Courseiva
Security →hardMultiple Select

FC0-U71 Security Practice Question

A user receives a suspicious email with an attachment claiming to be an invoice. Which three practices should the user follow? (Select THREE.)

⚠ Common exam trap

FC0-U71 often tests the misconception that opening an attachment to verify its content is a safe practice, when in fact it directly triggers the malware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Do not download unexpected attachments

Option A is correct because unexpected attachments are a primary malware and phishing delivery vector, so the user should not download or open them. Option B is correct because attackers often spoof or typosquat sender addresses, so carefully verifying the sender's actual email address helps confirm legitimacy. Option D is correct because hovering over a link reveals the true destination URL in the status bar or tooltip, exposing mismatched or malicious domains before any click. Option C is wrong because forwarding a suspicious email to all employees can spread malicious links or attachments and cause panic; it should instead be reported to IT/security. Option E is wrong because downloading and opening the attachment to inspect it can execute malicious code and compromise the user's system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Do not download unexpected attachments

    Why this is correct

    Avoiding unexpected attachments removes the malware delivery vector entirely, since invoice-themed phishing relies on the user opening the file to execute its payload. This satisfies the stem's suspicious-email constraint without depending on antivirus detection or sender verification, both of which can fail against newly crafted lures.

  • ✓

    Verify the sender's email address carefully

    Why this is correct

    Attackers spoof display names to impersonate trusted senders, so inspecting the full email address exposes mismatched or lookalike domains. This directly counters the invoice lure in the stem by confirming the sender's true identity before any interaction.

  • ✗

    Forward the email to all employees for awareness

    Why it's wrong here

    Forwarding a suspected phishing email to all employees spreads any malicious links or attachments and can trigger further compromise, rather than containing the threat. Mass distribution is intended for legitimate internal announcements, not for reporting suspicious messages, which should go to the security team or IT helpdesk for analysis and blocking.

  • ✓

    Hover over any links to see the actual URL before clicking

    Why this is correct

    Hovering reveals the destination URL without triggering it, exposing mismatched or deceptive domains hidden behind innocent-looking link text. This lets the user judge the invoice email's links safely, satisfying the requirement to avoid clicking malicious destinations.

  • ✗

    Download and open the attachment to check its content

    Why it's wrong here

    Opening the attachment executes whatever payload it carries, potentially installing malware or harvesting credentials, which is exactly what the attacker intends. Attachments are meant to be opened when the sender and content are verified as legitimate; here the invoice pretext is unverified, so the file must be reported and deleted without opening.

About these practice questions

One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.