220-1202 · Question #16
A small office reported a phishing attack that resulted in a malware infection. A technician is investigating the incident and has verified the following: - All endpoints are updated and have the…
The correct answer is B. Discuss the cause of the issue and educate the end user about security hygiene. With technical controls updated, EDR signatures current, and the infected system reimaged, the next step is to address the human factor. Educating the user on how to recognize phishing attempts and follow safe practices helps prevent recurrence and strengthens the…
Question
A small office reported a phishing attack that resulted in a malware infection. A technician is investigating the incident and has verified the following:
- All endpoints are updated and have the newest EDR signatures.
- Logs confirm that the malware was quarantined by EDR on one system.
- The potentially infected machine was reimaged.
Which of the following actions should the technician take next?
Options
- AInstall network security tools to prevent downloading infected files from the internet.
- BDiscuss the cause of the issue and educate the end user about security hygiene.
- CFlash the firmware of the router to ensure the integrity of network traffic.
- DSuggest alternate preventative controls that would include more advanced security software.
How the community answered
(21 responses)- A5% (1)
- B81% (17)
- C5% (1)
- D10% (2)
Explanation
With technical controls updated, EDR signatures current, and the infected system reimaged, the next step is to address the human factor. Educating the user on how to recognize phishing attempts and follow safe practices helps prevent recurrence and strengthens the organization's overall security posture.
Topics
Community Discussion
No community discussion yet for this question.