An employee emailed a new systems administrator a malicious web link and convinced the administrator to change the email server’s password. The employee used this access to remove the mailboxes of key personnel. Which of the following security awareness concepts would help prevent this threat in the future?
Choose an answer
Tap an option to check your answer.
Correct answer: Recognizing phishing.
Why this is the answer
Recognizing phishing is the most direct solution because the employee used a malicious web link and social engineering (convincing the administrator to change a password) to gain unauthorized access. This is a classic phishing attack designed to trick users into revealing sensitive information or performing actions that compromise security. Situational awareness training is too broad; while it contributes to overall security, it doesn't specifically address the deceptive nature of this attack. Using password management is a good security practice but wouldn't prevent the initial compromise via phishing if the administrator was tricked into changing the password outside a secure manager. Reviewing email policies is also too broad and wouldn't directly prevent an administrator from falling for a phishing attempt.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed