Instructions and covered skills
Read each scenario carefully before selecting a response. Focus on the evidence provided rather than assumptions about the sender or message urgency. Do not get distracted by persuasive wording, logos, or familiar names. Turn off notifications and complete the assessment in a quiet setting. Choose the action that best protects accounts, devices, and organizational information. Review your selection before moving on.
Key Areas
This test examines the practical judgment used to recognize, contain, and report suspicious email. Candidates assess sender identities beyond the visible display name, distinguish lookalike domains from legitimate domains, and recognize social-engineering patterns such as urgency, authority pressure, secrecy, and unusual payment requests. They interpret common authentication signals, including SPF, DKIM, and DMARC results, as supporting evidence rather than as isolated proof that a message is safe or malicious.
The assessment also covers safe handling of links and attachments. This includes inspecting URLs without opening them, recognizing domain mismatches and deceptive subdomains, treating unexpected files with caution, and using approved security tools or reporting workflows. Candidates should understand how phishing can target credentials, financial transactions, cloud-sharing access, multifactor authentication, and business relationships.
Reporting and containment are central skills. Strong performance requires preserving relevant evidence, using the organization’s designated reporting mechanism, avoiding replies or forwarded copies that could spread the message, and taking prompt account-protection actions after suspected credential exposure. Scenarios also assess appropriate verification methods for high-impact requests, especially requests involving banking details, payroll changes, gift cards, invoices, or confidential data.
Recommended Preparation
Review examples of legitimate and fraudulent email domains, including typosquatting, character substitution, deceptive subdomains, and reply-to mismatches. Practice reading message headers and identifying the difference between visible sender information, return-path data, and delivery information. Become familiar with the organization’s phishing-reporting button, help desk process, and incident response contacts.
Study safe verification practices for requests that involve money, account credentials, sensitive documents, or changes to trusted contact details. Use independently sourced phone numbers, known internal directories, or established vendor contacts rather than contact details supplied by the suspicious message. Review how to reset passwords, revoke active sessions, and notify security personnel when credentials may have been entered on an untrusted site.