SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
An employee receives an email that appears to come from payroll and asks them to open a link to "confirm direct deposit details". The link goes to a site with a slightly misspelled company name. What should the employee do first?
⚠ Common exam trap
Candidates often think replying to the email (Option B) is a safe verification method, but in reality, it engages the attacker and confirms the email address as active, which is a common social engineering tactic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the company's known payroll portal or help desk contact to verify the request
The safest first step when receiving a suspicious email is to verify its legitimacy through a trusted, independent channel—such as the company's known payroll portal or the help desk. This avoids interacting with the potentially malicious link or sender, which could lead to credential theft or malware installation. The email exhibits classic phishing indicators: a spoofed sender, a request for sensitive action, and a URL with a misspelled domain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Click the link and sign in quickly before the account is locked
Why it's wrong here
Clicking the link and signing in quickly plays directly into the attacker's urgency tactic: the false 'account lock' deadline is designed to bypass your skepticism and rush you into entering credentials on a cloned, attacker-controlled page. Any credentials you submit there are captured and can be used to access the real payroll system or other corporate resources, while the original email remains undetected as the source of the compromise.
- ✗
Reply to the email and ask payroll whether the message is real
Why it's wrong here
Replying to the email and asking payroll whether the message is real still routes your response through the same untrusted channel—likely an attacker-controlled address that may be spoofing the payroll display name. It confirms to the attacker that your email address is active and monitored, and the reply could be met with a further social engineering attempt, such as a malicious attachment or a follow-up link, increasing the risk of compromise.
- ✓
Use the company's known payroll portal or help desk contact to verify the request
Why this is correct
Verifying through the company's known payroll portal or help desk contact is the correct, secure response because it uses a trusted, out-of-band channel that bypasses every component of the suspicious email—its links, its reply address, and its embedded payload. By navigating directly to the official portal or calling a verified number, you confirm the legitimacy of the request without ever exposing your credentials or confirming your address to a potential attacker.
- ✗
Forward the message to co-workers so they can compare it with similar emails
Why it's wrong here
Forwarding the message to co-workers amplifies the risk instead of mitigating it: if the email is malicious, each forwarded copy is another opportunity for someone to click the link, enter credentials, or trigger a payload, turning a single-target phish into a multi-user incident. Additionally, internal email forwarding may bypass perimeter security filters that would have flagged the message, and it does nothing to verify the original request—it only spreads the threat.
Go deeper
Related to this question
Learn chapter
Malware Types and Characteristics
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.