CompTIA A+ Core 2 (220-1002) — Question 59
Joe, a user, reports that several of his colleagues have received a suspicious email from his account that he did not send. A technician asks one of the colleagues to forward the email for inspection. After ruling out spoofing, the technician verifies the email originated from the corporate email server.
Which of the following is the FIRST step the technician should take to correct this issue?
Answer options
- A. See if Joe's email address has been blacklisted
- B. Change the password on Joe's email account
- C. Update the antivirus and perform a full scan on the PC
- D. Isolate Joe's computer from the network
Correct answer: D
Explanation
The first action should be to isolate Joe's computer from the network to prevent any potential spread of malware or further unauthorized access. Changing the password or updating antivirus software are important, but they should come after ensuring that no additional harm can occur while the issue is being investigated.