How Should Security Teams Respond to Phishing Emails Using URL Shorteners?
A security team has been alerted to a flood of incoming emails that have various subject lines and are addressed to multiple email inboxes. Each email contains a URL shortener link that is redirecting to a dead domain. Which of the following is the best step for the security team to take?
Community Votes
50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests your ability to identify the most reliable choke point in an obfuscated attack chain, trapping candidates who fixate on the currently inactive redirect domain instead of the abused shortening service.
This question examines proactive mitigation strategies for phishing campaigns leveraging URL shorteners, with the community favoring immediate proxy blocking over endpoint-focused controls. The consensus emphasizes neutralizing the persistent delivery mechanism to prevent future malicious redirections.
Many candidates select sending the dead domain to a DNS sinkhole, mistakenly believing that managing the inactive endpoint resolves the threat without recognizing that attackers routinely rotate targets through the same abbreviation service.
Community Discussion (13 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept Analysis
The scenario describes a coordinated phishing campaign utilizing URL shorteners to obscure malicious destinations. Even though the final redirect points to a dead domain, the underlying attack infrastructure remains a significant risk because attackers can instantly reconfigure the shortener to point to newly registered malicious sites. Blocking the URL shortener domain directly at the web proxy is the most effective mitigating control. As noted by community experts, this proactive measure ensures that employees cannot access any future payloads routed through that specific abbreviation service, effectively neutralizing the entire campaign vector [[1], [3], [4]].Why Other Options Fall Short
Option A is impractical due to the varying subject lines and would likely result in excessive false positives. Option C suggests quarantining all emails, which creates operational friction and does not address the underlying technical threat; additionally, indiscriminate quarantine disrupts business continuity [[10]]. Option B, sending the dead domain to a DNS sinkhole, is the most common distractor. While sinkholing is excellent for capturing traffic to known malicious infrastructure, it only addresses the current endpoint. Candidates often fall for this trap because they focus on the "dead" aspect rather than the persistence of the shortener abuse model [[2], [12]]. Once the attacker updates the redirect target, a sinkholed dead domain becomes irrelevant to stopping new clicks.Strategic Implementation
In real-world Security Operations, combining web proxy filtering with email gateway URL rewriting provides layered protection. However, for certification purposes, you must prioritize the control that stops the attack at its most reliable choke point. Since URL shorteners act as the gateway for the payload, blocking them at the network perimeter delivers immediate and sustained mitigation across the organization.Official Reference
- CompTIA Security+ SY0-701 Exam Objectives - Domain 4.4 (Implement Application Security Solutions)
- NIST Special Publication 800-61 Rev. 2 - Computer Security Incident Handling Guide
- MITRE ATT&CK Technique T1583.003 (Acquire Domain Names) & T1583.006 (Acquire Infrastructure)
Exam Strategy
When faced with phishing or malware scenarios involving dynamic or changing endpoints, always look for the control that blocks the persistent delivery mechanism rather than chasing transient payloads. On the SY0-701, prioritize solutions that provide immediate, organization-wide mitigation while minimizing operational disruption to legitimate business functions.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →