nerdexam
Cisco

300-215 · Question #43

An organization experienced a sophisticated phishing attack that resulted in the compromise of confidential information from thousands of user accounts. The threat actor used a land and expand…

The correct answer is A. investigation into the specific vulnerabilities or weaknesses in the organization's email security. A proper root-cause analysis pinpoints the control failures that allowed the phishing email to reach and deceive the first user - namely gaps in email filtering, authentication (SPF/DMARC), or user‐training defenses - so you can strengthen those exact layers to prevent…

Submitted by helene.fr· Mar 6, 2026Incident Response Processes

Question

An organization experienced a sophisticated phishing attack that resulted in the compromise of confidential information from thousands of user accounts. The threat actor used a land and expand approach, where initially accessed account was used to spread emails further. The organization's cybersecurity team must conduct an in-depth root cause analysis to uncover the central factor or factors responsible for the success of the phishing attack. The very first victim of the attack was user with email [email protected]. The primary objective is to formulate effective strategies for preventing similar incidents in the future. What should the cybersecurity engineer prioritize in the root cause analysis report to demonstrate the underlying cause of the incident?

Options

  • Ainvestigation into the specific vulnerabilities or weaknesses in the organization's email security
  • Bevaluation of the organization's incident response procedures and the performance of the incident
  • Cexamination of the organization's network traffic logs to identify patterns of unusual behavior
  • Dcomprehensive analysis of the initial user for presence of an insider who gained monetary value

How the community answered

(44 responses)
  • A
    82% (36)
  • B
    11% (5)
  • C
    5% (2)
  • D
    2% (1)

Explanation

A proper root-cause analysis pinpoints the control failures that allowed the phishing email to reach and deceive the first user - namely gaps in email filtering, authentication (SPF/DMARC), or user‐training defenses - so you can strengthen those exact layers to prevent recurrence.

Topics

#phishing#root cause analysis#incident analysis#email security

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice