The security practice that helped the manager identify the suspicious link is end-user training. Training users to recognize phishing attempts and other social engineering attacks, such as hovering over links to check the actual URL, is a critical component of an organization's security awareness program. End user training: Educates employees on how to identify and respond to security threats, including suspicious emails and phishing attempts. Policy review: Ensures that policies are understood and followed but does not directly help in identifying specific attacks. URL scanning: Automatically checks URLs for threats, but the manager identified the issue manually. Plain text email: Ensures email content is readable without executing scripts, but the identification in this case was due to user awareness.