IT Support Practical Case Series · Case 08

A Suspicious Email Has Been Reported

Se ha reportado un correo sospechoso

Handle a suspected phishing message safely while preserving evidence and limiting organizational risk.

Maneja un posible phishing de forma segura, preservando evidencia y limitando el riesgo.

7 minutes7 minutosPractical caseCaso prácticoCybersecurity firstCiberseguridad primeroCertificateCertificado
Step 1 · The incidentPaso 1 · El incidente

Understand the situation before taking action

Comprende la situación antes de actuar

ScenarioEscenario

A user reports an urgent email asking them to open an attachment and sign in to avoid account suspension.

Un usuario reporta un correo urgente que pide abrir un adjunto e iniciar sesión para evitar suspensión.

Cybersecurity FirstCiberseguridad primero

Do not click links, open attachments, reply, forward normally, or test credentials. Preserve evidence and follow the approved phishing-reporting process.

No hagas clic, abras adjuntos, respondas, reenvíes normalmente ni pruebes credenciales. Preserva evidencia y sigue el proceso aprobado.

Step 2 · Questions to askPaso 2 · Preguntas clave

Collect facts, not assumptions

Recopila hechos, no suposiciones

  • Did the user click, open, reply, or enter credentials?
  • What sender address and domain are shown?
  • Are there urgency, authority, payment, or credential requests?
  • Did other users receive the same message?
  • What approved reporting tool or process is available?
  • ¿El usuario hizo clic, abrió, respondió o ingresó credenciales?
  • ¿Qué remitente y dominio aparecen?
  • ¿Hay urgencia, autoridad, pago o solicitud de credenciales?
  • ¿Otros usuarios recibieron el mensaje?
  • ¿Qué proceso aprobado existe?
Professional habitHábito profesional

Record the exact message, time, scope, recent changes, and business impact. Precise notes shorten diagnosis and escalation.

Registra mensaje exacto, hora, alcance, cambios recientes e impacto. Las notas precisas aceleran diagnóstico y escalamiento.

Step 3 · Initial troubleshootingPaso 3 · Diagnóstico inicial

Start with safe, low-risk checks

Comienza con revisiones seguras y de bajo riesgo

  • Capture message details and headers through approved methods.
  • Inspect the display name, actual address, links, and attachment type without opening them.
  • Check for similar organizational reports.
  • Determine whether any interaction or credential exposure occurred.
  • Captura detalles y encabezados por métodos aprobados.
  • Inspecciona nombre, dirección, enlaces y tipo de adjunto sin abrir.
  • Busca reportes similares.
  • Determina si hubo interacción o exposición de credenciales.
Step 4 · Technical diagnosisPaso 4 · Diagnóstico técnico

Use scope and test results to isolate the cause

Usa alcance y resultados para aislar la causa

  • No interaction: report, contain, and educate.
  • Link clicked but no credentials: assess endpoint and session risk.
  • Credentials entered: initiate account-compromise response.
  • Attachment opened: isolate and escalate endpoint investigation.
  • Sin interacción: reporta, contiene y educa.
  • Enlace abierto sin credenciales: evalúa equipo y sesión.
  • Credenciales ingresadas: inicia respuesta por compromiso.
  • Adjunto abierto: aísla y escala investigación.
Step 5 · Possible resolutionsPaso 5 · Posibles resoluciones

Resolve safely, validate, and document

Resuelve de forma segura, valida y documenta

  • Submit the message using the approved reporting channel.
  • Block or remove the campaign through authorized security teams.
  • Reset credentials and revoke sessions when exposure is confirmed.
  • Isolate affected devices and preserve evidence when malware is possible.
  • Envía el mensaje por el canal aprobado.
  • Bloquea o elimina la campaña mediante seguridad autorizada.
  • Restablece credenciales y revoca sesiones si hubo exposición.
  • Aísla equipos y preserva evidencia si puede haber malware.
Before closingAntes de cerrar

Confirm the result with the user or approved monitoring, document the cause and actions, and record any remaining risk or follow-up.

Confirma el resultado con el usuario o monitoreo aprobado, documenta causa y acciones, y registra cualquier riesgo o seguimiento.

Step 6 · Five easy questionsPaso 6 · Cinco preguntas fáciles

Quick learning check

Comprobación rápida

This is not a formal exam. Select an option, then use “Check answer” to see the correct answer and explanation.

Esto no es un examen formal. Selecciona una opción y usa “Revisar respuesta” para ver la respuesta correcta y la explicación.

1. Should the attachment be opened to test it?1. ¿Debe abrirse el adjunto para probarlo?
Correct answer: NoRespuesta correcta: NoTesting suspicious content can cause harm.Testing suspicious content can cause harm.
2. What changes the urgency of the response most?2. ¿Qué cambia más la urgencia de la respuesta?
Correct answer: Whether the user interacted or entered credentialsRespuesta correcta: Si el usuario interactuó o ingresó credencialesUser interaction determines exposure.User interaction determines exposure.
3. What should be preserved?3. ¿Qué debe preservarse?
Correct answer: Message evidence and relevant detailsRespuesta correcta: Evidencia del mensaje y detalles relevantesSecurity teams need reliable evidence.Security teams need reliable evidence.
4. If credentials were entered, what is required?4. Si se ingresaron credenciales, ¿qué se requiere?
Correct answer: Account-compromise responseRespuesta correcta: Respuesta por compromiso de cuentaCredentials may already be exposed.Credentials may already be exposed.
5. How should the message be reported?5. ¿Cómo debe reportarse el mensaje?
Correct answer: Through the approved security processRespuesta correcta: Mediante el proceso de seguridad aprobadoUse approved tools that preserve evidence safely.Use approved tools that preserve evidence safely.
Step 7 · CertificatePaso 7 · Certificado

Create your certificate of participation

Crea tu certificado de participación

IT SUPPORT PRACTICAL CASE SERIES · CASE 08 OF 15
Certificate of Completion

This certifies that

has successfully completed

IT Support Practical Case 08
A Suspicious Email Has Been Reported

Completed a practical, cybersecurity-first support scenario focused on Phishing, Email Security, Incident Response, Social Engineering, and Awareness.

Skills Demonstrated
PhishingEmail SecurityIncident ResponseSocial EngineeringAwareness
Learning Time
7 minutes
Completion Date
Juan Carballo
Microsoft Certified Systems Engineer
Microsoft Certified Systems Administrator

Case Focus:Enfoque del caso: Phishing · Email Security · Incident Response · Social Engineering · Awareness