nerdexam
CompTIA

220-1102 · Question #364

A technician is concerned about a large increase in the number of whaling attacks happening in the industry. The technician wants to limit the company's risk to avoid any issues. Which of the followin

The correct answer is B. Firewall. To limit the company's risk from whaling attacks, implementing a firewall provides a foundational technical control to mitigate potential impacts.

Security

Question

A technician is concerned about a large increase in the number of whaling attacks happening in the industry. The technician wants to limit the company's risk to avoid any issues. Which of the following items should the technician implement?

Options

  • AScreened subnet
  • BFirewall
  • CAnti-phishing training
  • DAntivirus

How the community answered

(23 responses)
  • A
    9% (2)
  • B
    74% (17)
  • C
    4% (1)
  • D
    13% (3)

Why each option

To limit the company's risk from whaling attacks, implementing a firewall provides a foundational technical control to mitigate potential impacts.

AScreened subnet

A screened subnet typically segregates public-facing services from internal networks and does not directly prevent social engineering attacks like whaling against internal users.

BFirewallCorrect

A firewall can help limit the risk of whaling attacks by blocking access to known malicious websites and command-and-control servers that might be linked from a whaling email or become active after an initial compromise. It acts as a critical network security control that can prevent the execution or spread of malware resulting from a successful social engineering attempt, thereby limiting potential damage.

CAnti-phishing training

Anti-phishing training is highly effective at preventing users from falling victim to whaling attacks, but a firewall provides a technical, network-level implementation to block malicious traffic and mitigate the effects of an attack.

DAntivirus

Antivirus software protects against known malware signatures, but whaling attacks primarily exploit human trust and often don't involve direct execution of traditional virus files as the initial vector.

Concept tested: Network security for phishing mitigation

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/windows-firewall-with-advanced-security-overview

Topics

#Whaling#Firewall#Network Security#Social Engineering

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice