220-1002 · Question #622
After a successful phishing attempt on a corporate workstation, the workstation is infected with malware that went undetected by the antivirus. When a technician arrives to investigate the issue…
The correct answer is B. Educating the user. The root cause of the entire incident was a successful phishing attempt-meaning the user was deceived into an action that allowed malware to execute. Technical controls like antivirus failed because the malware went undetected. The only control that addresses the actual attack…
Question
After a successful phishing attempt on a corporate workstation, the workstation is infected with malware that went undetected by the antivirus. When a technician arrives to investigate the issue, the workstation is no longer in a bootable state. Recovery is not possible, and the operating system has to be reinstalled completely. Which of the following would MOST likely prevent a future infection?
Options
- ACreating regular restore points
- BEducating the user
- CScanning for viruses frequently
- DChanning to a different antivirus vendor
How the community answered
(38 responses)- A5% (2)
- B84% (32)
- C8% (3)
- D3% (1)
Explanation
The root cause of the entire incident was a successful phishing attempt-meaning the user was deceived into an action that allowed malware to execute. Technical controls like antivirus failed because the malware went undetected. The only control that addresses the actual attack vector (human deception) is user education: teaching users to recognize phishing emails, suspicious links, and social engineering tactics prevents the initial compromise from occurring in the first place. Creating restore points (A) helps with recovery but does not prevent infection. Scanning for viruses more frequently (C) would not have helped since the antivirus already failed to detect this malware. Changing antivirus vendors (D) may improve detection rates but does not address the human behavior that enabled the attack.
Topics
Community Discussion
No community discussion yet for this question.