easyMultiple Choice
FC0-U71 Practice Question: An employee receives an email from an unknown…
An employee receives an email from an unknown sender that includes an attachment labeled 'Invoice.pdf'. The employee does not recall ordering anything. What is the most secure action for the employee to take?
⚠ Common exam trap
A common mix-up: candidates think deleting the email is sufficient (Option D), but the exam emphasizes the importance of reporting security incidents to IT for organizational defense, not just individual action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Forward the email to the IT security team and then delete it.
The most secure action when receiving an unsolicited email with an attachment from an unknown sender is to forward it to the IT security team for analysis and then delete it. This prevents potential malware execution (e.g., macro-based payloads in PDFs) and allows the security team to investigate the threat, such as checking for phishing indicators or malicious scripts. Opening or replying could compromise the system or reveal user information, while simply deleting may miss the opportunity to alert others.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Open the attachment to check if it is a legitimate invoice.
Why it's wrong here
Opening the attachment executes potential malware or triggers a phishing payload before any verification occurs. It is tempting because inspecting the file appears to confirm whether the invoice is real, but attachments from unknown senders should be treated as hostile and never opened.
- ✗
Reply to the sender requesting more information.
Why it's wrong here
Replying confirms the address is live and engages the attacker, and the sender's answer cannot verify legitimacy. It is tempting as due diligence when an invoice might be genuine, but verification should occur through known contact channels, not by responding to unsolicited email.
- ✓
Forward the email to the IT security team and then delete it.
Why this is correct
Reporting to the IT security team lets specialists analyse the suspicious attachment in a sandboxed environment and block the sender domain for everyone, while deletion alone removes the evidence and leaves other recipients exposed to the same phishing campaign.
- ✗
Delete the email without opening any attachments.
Why it's wrong here
Deleting the message leaves the malicious sender free to target others and discards evidence; the secure action is reporting it to security or IT without opening the attachment. It is tempting because deletion removes the immediate threat from the inbox, and would be correct for clearly benign spam rather than a suspected phishing attempt.
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.