FC0-U71 Security Practice Question
A user receives a text message claiming to be from a package delivery service, saying a package could not be delivered and asking the user to click a link to reschedule. The user is unsure if the message is legitimate. Which TWO of the following actions should the user take to verify the message and avoid becoming a victim? (Choose two.)
⚠ Common exam trap
The trap here is thinking that clicking a link just to look is harmless, when it can lead to malware or credential theft.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Contact the delivery service using a phone number from its official website to confirm whether the message is real.
The safest actions are to verify the message through an official channel and to report it as phishing. Clicking links, replying, or asking friends do not confirm legitimacy and may expose the user to risk. Reporting helps prevent others from falling victim.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Contact the delivery service using a phone number from its official website to confirm whether the message is real.
Why this is correct
Verifying through an independent, trusted channel such as the official website ensures the user is not interacting with the attacker. This confirms whether the message is legitimate without risking exposure to malicious links or providing information to a fraudster. It is a recommended practice for suspected phishing attempts.
- ✗
Reply to the text message asking for more details about the package.
Why it's wrong here
Replying confirms that the phone number is active and that the user is willing to engage, which can lead to more targeted attacks. It also does not verify the sender's identity because the attacker controls the reply. Users should not respond to unsolicited messages that request action.
- ✗
Forward the message to a friend to ask if they received a similar one.
Why it's wrong here
Asking a friend does not verify the legitimacy of the message and may spread the phishing attempt. The friend's experience is irrelevant to whether this specific message is real. The user should rely on official verification methods rather than informal opinions.
- ✗
Click the link to see if the website looks official before entering any information.
Why it's wrong here
Clicking the link can lead to a malicious website that may download malware or capture credentials even if the user does not enter information. Phishing sites often mimic legitimate ones closely. The safe approach is to avoid clicking links in unsolicited messages and instead verify through official channels.
- ✓
Report the message as spam or phishing using the phone's built-in reporting feature.
Why this is correct
Reporting the message helps the carrier and authorities block similar attacks and protects other users. It is a safe action that does not involve interacting with the attacker. Combined with independent verification, reporting is a best practice for handling suspected smishing attempts.
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.