How Did the Manager Identify the Suspicious Phishing Link?
A manager receives an email that contains a link to receive a refund. After hovering over the link, the manager notices that the domain's URL points to a suspicious link. Which of the following security practices helped the manager to identify the attack?
Community Votes
83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you can recognize that manually verifying a URL before clicking is a learned behavior resulting from security awareness training, not an automated system or policy document.
This question highlights the critical role of human vigilance in mitigating phishing threats, with the community strongly agreeing that security awareness training empowers employees to spot malicious indicators. It reinforces the distinction between technical security controls and behavioral best practices.
Candidates often select "URL scanning" because they equate the act of checking a link with automated web filtering or sandboxing tools. However, the scenario explicitly describes a manual human action driven by knowledge, making option C a distractor that confuses user behavior with technical controls.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Human-Centric Security Controls
Phishing and social engineering remain among the most effective attack vectors because they exploit human psychology rather than software vulnerabilities. In this scenario, the manager proactively hovers over a hyperlink to inspect the underlying domain—a classic red-flag detection technique.Why End User Training is Correct
End user training (Option A) is the foundational security practice that teaches employees how to recognize, report, and avoid social engineering tactics. As highlighted by multiple community members, the ability to identify a mismatched or suspicious domain after hovering stems directly from structured security awareness programs. These programs instill habits like verifying sender addresses, scrutinizing link destinations, and questioning unsolicited requests (e.g., unexpected refunds).Why Other Options Are Incorrect
- Policy review (Option B) involves auditing or updating organizational rules and procedures. While policies may mandate reporting suspicious emails, reviewing them does not teach a user how to technically or visually verify a URL.
- URL scanning (Option C) refers to automated security tools that analyze web addresses against threat intelligence databases in real-time. Community member jsmthy noted that while the manager is "scanning" the URL manually, this is a behavioral action, not a deployed security product or service.
- Plain text email (Option D) is an email format without HTML formatting. It actually reduces certain phishing risks (like masked buttons) but has no bearing on the manager's ability to detect a malicious link destination.
Exam Takeaway
CompTIA frequently uses scenario-based questions to differentiate between technical controls (firewalls, scanners, encryption) and administrative/human controls (training, policies, background checks). Always map the actor in the scenario to the appropriate control type.Official Reference
- https://www.comptia.org/content/guidelines/security-sy0-701-guide
- NIST Special Publication 800-50: Building an Information Technology Security Awareness and Training Program
- MITRE ATT&CK: Initial Access Tactics (TA0001)
Exam Strategy
When a scenario describes a person manually verifying a suspicious artifact (URL, attachment, sender), immediately prioritize security awareness or end-user training over technical solutions. Carefully read who performed the action: if it was a human using learned judgment, it's a training outcome; if it was an automated system, look for technical controls.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →