ASSOCIATE-GOOGLE-WORKSPACE-ADMINISTRATOR · Question #32
You've noticed an increase in phishing emails that contain links to malicious files hosted on external Google Drives. These files often mimic legitimate documents and trick users into granting…
The correct answer is B. Conduct regular security awareness training to educate users. C. Create a Drive trust rule that blocks all external domains except for a pre-approved list of trusted. Two measures are needed that specifically address phishing via malicious external Drive files while still allowing legitimate external file access. Option B (security awareness training) is essential-educated users can recognize and avoid clicking suspicious links, directly…
Question
You've noticed an increase in phishing emails that contain links to malicious files hosted on external Google Drives. These files often mimic legitimate documents and trick users into granting access to their accounts. You need to prevent users from accessing these malicious external Drive files, but allow them to access legitimate external files. What should you do? (Choose two.)
Options
- AEnforce stricter password policies.
- BConduct regular security awareness training to educate users.
- CCreate a Drive trust rule that blocks all external domains except for a pre-approved list of trusted
- DDeploy advanced malware detection software on all user devices to scan and block malicious files.
- EImplement two-factor authentication for all users
How the community answered
(70 responses)- A13% (9)
- B80% (56)
- D3% (2)
- E4% (3)
Explanation
Two measures are needed that specifically address phishing via malicious external Drive files while still allowing legitimate external file access. Option B (security awareness training) is essential-educated users can recognize and avoid clicking suspicious links, directly reducing the attack surface. Option C (Drive trust rules allowing only pre-approved external domains) is a technical control that directly blocks access to files hosted on untrusted external Google Drives while permitting access to approved ones, precisely matching the requirement. Option A (stronger passwords) does not prevent users from clicking links to external files. Option D (endpoint malware detection) is less effective against cloud-hosted social engineering lures. Option E (2FA) is good security hygiene but does not prevent a user from willingly opening a malicious file link.
Topics
Community Discussion
No community discussion yet for this question.