How Should Security Teams Respond to Phishing Emails Using URL Shorteners?

A security team has been alerted to a flood of incoming emails that have various subject lines and are addressed to multiple email inboxes. Each email contains a URL shortener link that is redirecting to a dead domain. Which of the following is the best step for the security team to take?

  1. Create a blocklist for all subject lines.
  2. Send the dead domain to a DNS sinkhole.
  3. Quarantine all emails received and notify all employees.
  4. Block the URL shortener domain in the web proxy. Source Reference Answer

Community Votes

D
50%
B
50%

50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests your ability to identify the most reliable choke point in an obfuscated attack chain, trapping candidates who fixate on the currently inactive redirect domain instead of the abused shortening service.

This question examines proactive mitigation strategies for phishing campaigns leveraging URL shorteners, with the community favoring immediate proxy blocking over endpoint-focused controls. The consensus emphasizes neutralizing the persistent delivery mechanism to prevent future malicious redirections.

Many candidates select sending the dead domain to a DNS sinkhole, mistakenly believing that managing the inactive endpoint resolves the threat without recognizing that attackers routinely rotate targets through the same abbreviation service.

Community Discussion (13 comments)

RoRoRoYourBoat 👍 12 Selected: D
D. Block the URL shortener domain in the web proxy: By blocking the URL shortener domain, the security team can prevent users from accessing potentially malicious links, even if the domain is currently dead. This proactive measure helps mitigate the risk of future attacks using the same URL shortener.
laternak26 👍 10 Selected: B
NOT D. Block the URL shortener domain in the web proxy: Blocking the URL shortener domain in the web proxy is a good idea if you suspect that the malicious URLs lead to a harmful site, but in this case, the links are redirecting to a dead domain. The malicious domain itself is no longer active, so blocking the URL shortener might not address the immediate threat. Additionally, this step doesn't prevent other similar attacks with different shorteners or domains in the future.
skg01 👍 1 Selected: D
D. Block the URL shortener domain in the web proxy. Explanation: Since the attack uses URL shorteners to redirect users to potentially malicious domains, the most effective mitigation is to block the URL shortener domain in the web proxy. This prevents employees from clicking on similar links in the future, even if the attacker changes the final redirect destination. Why not the other options? A. Create a blocklist for all subject lines – Not effective because attackers can easily modify subject lines to bypass filters. B. Send the dead domain to a DNS sinkhole – The domain is already dead, meaning it is no longer actively serving content. The threat lies in the URL shortener, which may redirect to different malicious sites in future attacks. C. Quarantine all emails received and notify all employees – While notifying employees is important, quarantining all emails may cause unnecessary disruptions. Blocking the URL shortener is a more effective preventive measure.
mejestique 👍 1 Selected: D
D. Block the URL shortener domain in the web proxy. Explanation: URL shorteners are often used in phishing attacks and malware distribution to obscure malicious links. Even though the current redirect domain is dead, attackers can update the shortener to point to a new malicious domain at any time. Blocking the URL shortener domain at the web proxy ensures that: Users cannot access any future malicious redirects coming from that shortener. The security team prevents future attacks using the same shortener service. It applies a broad and proactive security measure rather than reacting to just the current incident.
selom1 👍 1 Selected: D
This provides immediate protection against current campaign
DaBulls 👍 1 Selected: D
The issue involves a URL shortener that redirects to a dead domain. Blocking the URL shortener domain prevents any redirection attempts, regardless of the destination domain. This measure also addresses any future malicious redirections from the same shortener. Send the dead domain to a DNS sinkhole: While this may help if the dead domain becomes active again, it does not address the possibility of the URL shortener being used for other malicious redirections.
amccert 👍 1 Selected: C
Jsmithy Response was on point look at his explanation
Eracle 👍 2 Selected: D
Even if the domain they redirect URLs to is currently dead, the URL could be reactivated in the future for malicious purposes.
gingergroot 👍 3 Selected: B
B. GPT
jsmthy 👍 2 Selected: C
Quarantine is correct. The dead domain may not do anything, but there can be several layers of redirects. You can place the dead domain on the DNS sinkhole, but that won't prevent users from clicking the links. If you block the URL shortener, you could block legitimate traffic to that shortener.
dhewa 👍 2 Selected: B
Well D is an option but it might not address the root cause if the attacker switches to a different URL shortener.
nyyankee718 👍 3 Selected: B
URL shortener will not block everything
Hayder81 👍 2
D. Block the URL shortener domain in the web proxy:

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept Analysis

The scenario describes a coordinated phishing campaign utilizing URL shorteners to obscure malicious destinations. Even though the final redirect points to a dead domain, the underlying attack infrastructure remains a significant risk because attackers can instantly reconfigure the shortener to point to newly registered malicious sites. Blocking the URL shortener domain directly at the web proxy is the most effective mitigating control. As noted by community experts, this proactive measure ensures that employees cannot access any future payloads routed through that specific abbreviation service, effectively neutralizing the entire campaign vector [[1], [3], [4]].

Why Other Options Fall Short

Option A is impractical due to the varying subject lines and would likely result in excessive false positives. Option C suggests quarantining all emails, which creates operational friction and does not address the underlying technical threat; additionally, indiscriminate quarantine disrupts business continuity [[10]]. Option B, sending the dead domain to a DNS sinkhole, is the most common distractor. While sinkholing is excellent for capturing traffic to known malicious infrastructure, it only addresses the current endpoint. Candidates often fall for this trap because they focus on the "dead" aspect rather than the persistence of the shortener abuse model [[2], [12]]. Once the attacker updates the redirect target, a sinkholed dead domain becomes irrelevant to stopping new clicks.

Strategic Implementation

In real-world Security Operations, combining web proxy filtering with email gateway URL rewriting provides layered protection. However, for certification purposes, you must prioritize the control that stops the attack at its most reliable choke point. Since URL shorteners act as the gateway for the payload, blocking them at the network perimeter delivers immediate and sustained mitigation across the organization.

Official Reference

  • CompTIA Security+ SY0-701 Exam Objectives - Domain 4.4 (Implement Application Security Solutions)
  • NIST Special Publication 800-61 Rev. 2 - Computer Security Incident Handling Guide
  • MITRE ATT&CK Technique T1583.003 (Acquire Domain Names) & T1583.006 (Acquire Infrastructure)

Exam Strategy

When faced with phishing or malware scenarios involving dynamic or changing endpoints, always look for the control that blocks the persistent delivery mechanism rather than chasing transient payloads. On the SY0-701, prioritize solutions that provide immediate, organization-wide mitigation while minimizing operational disruption to legitimate business functions.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide