ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
During a weekly on-call rotation, a DevOps engineer receives an unsolicited phone call from someone claiming to be from AWS Support. The caller says an urgent breach investigation requires the engineer's current virtual MFA token to validate access. Which action BEST reflects proper security-awareness handling of this social engineering attempt?
Provide the MFA code after the caller sends a follow-up email from what appears to be an aws.com address.
Immediately hang up and disable the IAM user mentioned by the caller to prevent any possible misuse.
Decline to share the MFA code, end the call, and open a new case using the AWS console's official support channels.
Request the caller sign a nondisclosure agreement, then share the MFA code once the document is returned.
Voice calls requesting credentials or MFA tokens are a form of vishing. AWS Support will never call and ask for temporary codes or passwords. The safest response is to refuse the request, terminate the call, and independently open a new support case through the AWS Management Console or the published AWS phone number to verify any legitimate issue. Providing the token after an email, demanding an NDA, or hastily disabling an IAM user does not stop potential account compromise and may disrupt operations without confirming the caller's legitimacy.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is vishing and how does it differ from phishing?
Open an interactive chat with Bash
Why should an MFA token never be shared, even with someone claiming to be support?
Open an interactive chat with Bash
How can you verify legitimate communication from AWS Support?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .