350-201(NEW-127Q) · Question #23
A security analyst is reviewing a playbook scenario that describes the steps to be taken in response to a phishing attack targeting the organization. The scenario includes the identification and…
The correct answer is D. Email filtering solution, malware analysis sandbox, and incident response management platform. Option D is correct because each tool directly maps to a step in the playbook: an email filtering solution identifies and contains phishing emails at the delivery layer, a malware analysis sandbox safely analyzes suspicious payloads in isolation, and an incident response…
Question
Options
- AIntrusion detection system, network packet analyzer, and SIEM
- BDLP solution, WAF, and multifactor authentication system
- CVulnerability scanner, penetration testing tool, and UEBA system
- DEmail filtering solution, malware analysis sandbox, and incident response management platform
How the community answered
(38 responses)- A3% (1)
- B5% (2)
- C11% (4)
- D82% (31)
Explanation
Option D is correct because each tool directly maps to a step in the playbook: an email filtering solution identifies and contains phishing emails at the delivery layer, a malware analysis sandbox safely analyzes suspicious payloads in isolation, and an incident response management platform coordinates communication with affected users and tracks the response workflow - covering all three described phases.
Option A (IDS, packet analyzer, SIEM) focuses on network-level detection and log aggregation - useful for broader threat monitoring, but none of these tools specifically address phishing email containment or malware detonation.
Option B (DLP, WAF, MFA) are preventive/access control tools. They reduce attack surface but do not help respond to an active phishing incident already in progress.
Option C (vulnerability scanner, pen testing tool, UEBA) are offensive/behavioral analytics tools used for proactive security assessments, not incident response to a live phishing attack.
Memory tip: Match each tool to a playbook phase - Filter (stop the email) → Sandbox (analyze the payload) → IRP (manage and communicate). If the scenario describes a phishing response workflow with three phases, look for the answer that has exactly one tool per phase.
Topics
Community Discussion
No community discussion yet for this question.