nerdexam
CompTIA

220-1002 · Question #635

Ann, a user, received an email from an unknown source with an attachment claiming to be pictures from her beach vacation. When Ann opened the attachment, she was prompted to enable macros. Once the…

The correct answer is C. A content scanner. A content scanner (C) is the best first line of defense here because it intercepts and inspects email attachments and embedded content at the mail gateway - before a malicious file ever reaches the end user's inbox. In this scenario, Ann was able to open and interact with the…

Networking

Question

Ann, a user, received an email from an unknown source with an attachment claiming to be pictures from her beach vacation. When Ann opened the attachment, she was prompted to enable macros. Once the macros were enabled, the antivirus software triggered an alert. The malicious activity was stepped by the antivirus software. Which of the following should be recommended as the FIRST line of defense to prevent this attack vector from reoccurring?

Options

  • AA trusted CA
  • BAn outgoing proxy
  • CA content scanner
  • DA stateful firewall

How the community answered

(28 responses)
  • A
    11% (3)
  • B
    4% (1)
  • C
    79% (22)
  • D
    7% (2)

Explanation

A content scanner (C) is the best first line of defense here because it intercepts and inspects email attachments and embedded content at the mail gateway - before a malicious file ever reaches the end user's inbox. In this scenario, Ann was able to open and interact with the attachment, meaning the threat bypassed all upstream defenses. A content scanner would analyze the attachment for macro-enabled documents, known malware signatures, and suspicious payloads before delivery. Option A (trusted CA) addresses certificate trust, not email attachment filtering. Option B (outgoing proxy) filters outbound web traffic, not inbound email threats. Option D (stateful firewall) inspects network connection states but does not perform deep content inspection of email attachments. The attack vector here is phishing with a malicious macro-enabled document - a content scanner directly addresses that at the delivery layer.

Topics

#content scanner#email security#malware prevention#social engineering

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice