How Did the Manager Identify the Suspicious Phishing Link?

A manager receives an email that contains a link to receive a refund. After hovering over the link, the manager notices that the domain's URL points to a suspicious link. Which of the following security practices helped the manager to identify the attack?

  1. End user training Source Reference Answer
  2. Policy review
  3. URL scanning
  4. Plain text email

Community Votes

A
83%
C
17%

83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you can recognize that manually verifying a URL before clicking is a learned behavior resulting from security awareness training, not an automated system or policy document.

This question highlights the critical role of human vigilance in mitigating phishing threats, with the community strongly agreeing that security awareness training empowers employees to spot malicious indicators. It reinforces the distinction between technical security controls and behavioral best practices.

Candidates often select "URL scanning" because they equate the act of checking a link with automated web filtering or sandboxing tools. However, the scenario explicitly describes a manual human action driven by knowledge, making option C a distractor that confuses user behavior with technical controls.

Community Discussion (7 comments)

chalaka 👍 1 Selected: A
A. End user training Explanation: The manager identified the suspicious link by recognizing a discrepancy in the domain's URL. This ability likely comes from end-user training on phishing and other cybersecurity threats. Such training teaches employees to carefully examine links, avoid clicking on unknown or suspicious URLs, and recognize common red flags of phishing attacks.
3dk1 👍 1 Selected: A
A, User training
Murtuza 👍 1 Selected: A
The correct answer is A. End user training. End user training helps employees recognize phishing attempts and other security threats by teaching them to look for signs such as suspicious URLs. This training empowers users to identify and avoid potential security risks effectively
nillie 👍 2 Selected: A
The security practice that helped the manager identify the attack is: A. End user training End user training teaches employees how to recognize phishing attempts and other malicious activities. In this case, the manager's awareness of hovering over links to check for suspicious URLs before clicking is a direct result of effective security awareness training. This is a key aspect of preventing social engineering attacks, like phishing.
jsmthy 👍 1 Selected: C
The manager is scanning a URL. End-user training may make the practice of checking URLs more prevalent, but it is not the security practice being demonstrated.
rabid_adobo 👍 1
A. GPT
Ina22 👍 2
A. End user training

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Human-Centric Security Controls

Phishing and social engineering remain among the most effective attack vectors because they exploit human psychology rather than software vulnerabilities. In this scenario, the manager proactively hovers over a hyperlink to inspect the underlying domain—a classic red-flag detection technique.

Why End User Training is Correct

End user training (Option A) is the foundational security practice that teaches employees how to recognize, report, and avoid social engineering tactics. As highlighted by multiple community members, the ability to identify a mismatched or suspicious domain after hovering stems directly from structured security awareness programs. These programs instill habits like verifying sender addresses, scrutinizing link destinations, and questioning unsolicited requests (e.g., unexpected refunds).

Why Other Options Are Incorrect

  • Policy review (Option B) involves auditing or updating organizational rules and procedures. While policies may mandate reporting suspicious emails, reviewing them does not teach a user how to technically or visually verify a URL.
  • URL scanning (Option C) refers to automated security tools that analyze web addresses against threat intelligence databases in real-time. Community member jsmthy noted that while the manager is "scanning" the URL manually, this is a behavioral action, not a deployed security product or service.
  • Plain text email (Option D) is an email format without HTML formatting. It actually reduces certain phishing risks (like masked buttons) but has no bearing on the manager's ability to detect a malicious link destination.

Exam Takeaway

CompTIA frequently uses scenario-based questions to differentiate between technical controls (firewalls, scanners, encryption) and administrative/human controls (training, policies, background checks). Always map the actor in the scenario to the appropriate control type.

Official Reference

Exam Strategy

When a scenario describes a person manually verifying a suspicious artifact (URL, attachment, sender), immediately prioritize security awareness or end-user training over technical solutions. Carefully read who performed the action: if it was a human using learned judgment, it's a training outcome; if it was an automated system, look for technical controls.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide