SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
An employee receives an email that appears to come from the company's payroll provider. It says payroll documents will be deleted today unless the employee signs in through the included link. What is the best first action?
⚠ Common exam trap
Watch out — candidates often think replying to the sender (Option C) is a safe way to verify legitimacy, but in reality, it confirms the email address as active and can expose the user to further social engineering or malware delivery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the message and verify the request using a trusted contact method.
The email exhibits classic signs of a phishing attack—urgency, a threat of data loss, and a link to a fake login page. The best first action is to report the suspicious message to the security team and independently verify the request by contacting the payroll provider through a trusted channel (e.g., a known phone number or a previously bookmarked URL). This prevents credential theft and potential account compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Click the link quickly and sign in to avoid losing the documents.
Why it's wrong here
Clicking the link and entering credentials on the resulting page directly exposes the employee to phishing: the URL likely points to a lookalike login portal or a credential-harvesting service, possibly using a redirect or open redirect. Additionally, the link may initiate a drive-by download or exploit a browser vulnerability, and the urgency tactic is a hallmark of social engineering designed to bypass careful evaluation. Without verifying the sender via an independent channel, the employee risks account compromise before security can respond.
- ✓
Report the message and verify the request using a trusted contact method.
Why this is correct
Reporting the message to the security team or IT service desk preserves forensic evidence and allows the organization to check for similar campaigns or indicators of compromise. Verifying the request through a trusted contact method—such as a phone number from an internal directory or a known good URL—confirms whether the document link is legitimate or a social-engineering attempt. This approach neutralizes the phishing vector without engaging the suspicious content, and it aligns with incident response and user awareness training.
- ✗
Reply to the sender and ask whether the message is legitimate.
Why it's wrong here
Replying to the sender merely sends data to the address displayed in the 'From' header, which can be spoofed or the account compromised, so the answer may come from the attacker. It also confirms to the attacker that the email address is active and monitored, increasing the likelihood of follow-up targeted phishing or spear-phishing. Direct reply does not validate the authenticity of the message, because modern email authentication (SPF, DKIM, DMARC) is not necessarily checked or enforced by the client.
- ✗
Forward the email to coworkers so they can watch for the same warning.
Why it's wrong here
Forwarding the email to coworkers exposes them to the same malicious link or attachment, amplifying the risk of account compromise across the organization. In some environments, forwarding can trigger automated security scans or even cause the email to be delivered to further inboxes, and the act of forwarding itself can serve as a signal to the attacker that the campaign is working. The correct action is to isolate the message, not to propagate it.
Go deeper
Related to this question
Learn chapter
Phishing, Vishing, and Smishing
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.