Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

An employee receives an email that appears to be from the CEO and asks for gift cards before a meeting. What should the employee do first?

⚠ Common exam trap

Many candidates think immediate action (buying gift cards) shows responsiveness, but the exam emphasizes that verification and reporting are the mandatory first steps in any social engineering incident response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Report the message through the approved security channel and verify the request by a separate method.

The first action in response to a suspected phishing or social engineering attack is to report it through the approved security channel, which ensures the incident is logged and can be investigated. Separately verifying the request—such as by calling the CEO or using a known, trusted contact method—confirms the legitimacy of the request without relying on the potentially compromised email thread. This aligns with security policy best practices for incident response and prevents unauthorized disclosure of funds or credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Report the message through the approved security channel and verify the request by a separate method.

    Why this is correct

    This is correct because urgent gift card requests are a common social engineering tactic. The safest first step is to report the message and verify the request using a known, separate contact method. That prevents accidental compliance and helps the security team evaluate whether the email is fraudulent.

  • Buy the gift cards immediately so the CEO is not delayed.

    Why it's wrong here

    Acting on the email's urgency is exactly the psychological trigger used in gift card and Business Email Compromise scams; the attacker relies on the employee skipping verification to avoid 'delaying' the CEO. Even if the display name and signature match, the message can be spoofed or originate from a compromised account, so purchasing cards immediately converts untraceable funds to the attacker. Legitimate executives rarely demand urgent gift card purchases via email, and most organizations' policies require confirming financial requests through a known, separate channel, making this action both financially and procedurally dangerous.

  • Forward the email to coworkers so they can watch for the same request.

    Why it's wrong here

    Broadly forwarding the email to coworkers exposes them to the same malicious links, attachments, or reply-to addresses and may spread phishing lures beyond the intended target. It also contaminates the incident response picture: security teams need original headers and metadata to trace spoofing, but forwarding strips or alters that evidence and can generate a second wave of requests from confused users. Instead of acting as an ad hoc distribution list, the employee should report the message through the approved security channel so the SOC can analyze it and alert the organization safely.

  • Reply to the sender and ask for more details in the same email thread.

    Why it's wrong here

    Replying in the same email thread is not a valid verification because the attacker may control the 'CEO's' mailbox, or a spoofed domain can make the response appear to come from inside the organization. This interaction confirms that the address is active and can prompt the attacker to double down or send follow-up phishing attempts, and it bypasses the organization's detection controls because the exchange remains hidden from security monitoring. Only out-of-band contact—such as calling the CEO on a previously known number or using an authenticated collaboration tool—can establish whether the request is real.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.