The client wants to know if the candidate can recognize a potential social engineering or phishing attempt and follow a secure verification process before sharing any credentials. This screens for basic security awareness and composure under suspicious requests.
Explain that you would not reply with the password. Describe how you would verify the request through a separate channel, such as a known phone number or video call, and confirm the client's identity before taking any action. Mention that if you cannot verify, you would report the email and not share anything.
Start by saying plainly that you would not reply with the password, no matter how urgent the email sounds. Explain that a legitimate client who lost access would not ask you to send credentials through email, because that defeats the purpose of security. Then describe your verification process in concrete steps: you would check the sender address against your saved contact list, notice the mismatch, and flag it as suspicious. Say that you would reach out to your client through a separate, known channel, such as their mobile number on file or a video call, and ask them to confirm the request. If you cannot reach them or they do not recognize the email, you would report the incident to your supervisor or IT point person and delete the message without replying. In the Philippine context, you can add that you would keep your reply in English and stay calm, avoiding any Taglish apology like "Pasensya na po" because that invites pressure. Frame your answer around the idea that verifying first is faster than fixing a breach later, and that protecting the client's data is part of your job, not an inconvenience.
A common mistake is to reply quickly because you want to be helpful, saying something like 'Sige po, eto na po yung password' in Taglish, or over-apologizing for the delay. Instead, state clearly in English that you will first verify the request through a separate known contact before sharing any login information.
Situation
In my previous role as a virtual assistant for a small e-commerce business, I received an urgent email from an address that looked like my client's but used a different domain.
Task
I needed to determine whether the request was legitimate before sharing any login credentials, because sharing the password with the wrong person could compromise the client's entire store back end.
Action
I did not reply to the email. Instead, I called my client on the phone number we had on file and asked if they had sent the request. When they confirmed they had not, I marked the email as phishing, blocked the sender, and reported it to my client. I also reset the CRM password as a precaution, following the client's approval.
Result
The phishing attempt was stopped before any data was exposed. My client thanked me for verifying first and we added a rule that any credential requests must be confirmed by a quick call or chat on our approved platform.
Always verify unusual credential requests through a second channel before taking any action.
Write your own answer, then get instant AI feedback graded against:
Get AI feedback on your answer — free.
3 free AI-graded answers + 1 free mock interview, no card needed.
Sign Up FreeAlready have an account? Log in
Sign in to join the conversation.
No answers shared yet — be the first to show how you'd approach this.
Prioritizing a Full Inbox
Administrative Virtual Assistant
Onboarding Call Question Checklist
Administrative Virtual Assistant
Resolving Double-Booked Time Zones
Administrative Virtual Assistant
Decoding Client Shorthand Fast
Administrative Virtual Assistant