Courseiva
hardMultiple Choice

FC0-U71 Practice Question: An employee receives a phone call from someone…

An employee receives a phone call from someone claiming to be from the IT department. The caller states there is a security issue and requests the employee's login credentials to 'fix the problem'. What should the employee do?

⚠ Common exam trap

Watch out — candidates often think verifying the caller's identity later (Option D) is sufficient, but the correct procedure is to immediately terminate the call and independently verify using a trusted number, as call-back numbers can be spoofed or part of a coordinated attack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hang up and call the IT department using the official number.

The employee should never provide credentials in response to an unsolicited request, even if the caller sounds knowledgeable. Hanging up and calling the IT department using the official number ensures the request is verified through a trusted communication channel, preventing a social engineering attack such as phishing or pretexting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Give a temporary password to see if the issue resolves.

    Why it's wrong here

    Supplying any password, even temporary, hands credentials to an unverified caller and enables account compromise. Temporary passwords are issued by administrators through managed reset workflows, never verbally to inbound callers. The employee must refuse and report the suspected vishing attempt instead.

  • ✗

    Provide the credentials because the caller sounds knowledgeable.

    Why it's wrong here

    Legitimate IT staff never request passwords; the caller is likely conducting social engineering, so credentials must be withheld and the incident reported. Verification through a known internal contact is the correct step. Providing credentials would only be defensible to a verified, authorised identity through an approved process, which a cold call is not.

  • ✓

    Hang up and call the IT department using the official number.

    Why this is correct

    Verifying the caller through the IT department's official number defeats caller-ID spoofing, since the employee initiates contact rather than trusting an inbound request. Legitimate IT staff never need credentials, so refusing and independently confirming is the correct response.

  • ✗

    Ask for a call-back number and verify the caller's identity later.

    Why it's wrong here

    Verifying later still requires the employee to trust an unverified caller, and the credentials may already be compromised if disclosed. Call-back verification suits legitimate scheduled vendor contact, not unsolicited credential requests. The scenario demands refusing the request and reporting it through internal channels.

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.