What Should an Administrator Do When Employees Encounter Spoofed Websites?
An administrator at a small business notices an increase in support calls from employees who receive a blocked page message after trying to navigate to a spoofed website. Which of the following should the administrator do?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Examines the distinction between technical mitigations and behavioral interventions, trapping candidates who overlook user education in favor of immediate technical adjustments.
This scenario tests the critical role of human factors in cybersecurity defense strategies. Community consensus confirms that security awareness training is the definitive solution to reduce phishing susceptibility and lower support ticket volumes.
Candidates often select Option A (Deploy multifactor authentication), incorrectly assuming that stronger access controls will prevent users from navigating to malicious or spoofed domains in the first place.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Security awareness training directly addresses the root cause by educating employees on identifying phishing emails, spoofed URLs, and social engineering tactics. When staff understand how these attacks operate, they become less likely to click malicious links, significantly reducing support calls and potential breaches. CompTIA consistently prioritizes human-centric controls when technical barriers already flag the threat but users persistently attempt access.Why the Other Options Are Wrong
Deploying multifactor authentication secures account access but does not deter users from visiting dangerous sites or falling for initial deception. Decreasing web filter levels would actively weaken security posture by allowing more malicious traffic through, which contradicts the goal of protecting the network. Updating the acceptable use policy establishes rules but lacks the educational component required to change actual employee behavior and recognition skills.Community Comment Notes
Reviewers unanimously endorse option C, emphasizing that the surge in blocked pages signals a recurring human error pattern typical of targeted phishing campaigns. Comment [1] highlights that training helps employees recognize phishing and spoofed websites, while Comment [2] explains that the blocked page messages indicate ongoing social engineering attempts that require educational intervention. Several contributors stress that CompTIA favors proactive education over reactive technical tweaks in scenarios involving repeated employee mistakes.Official Reference
Exam Strategy
When faced with scenarios involving repeated user errors or phishing clicks, always evaluate whether a technical control has already been implemented. If yes, CompTIA expects you to select the human-risk management solution, such as training or policy enforcement with education, to close the behavioral gap.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →