nerdexam
CompTIA

CAS-003 · Question #349

A company has gone through a round of phishing attacks. More than 200 users have had their workstation infected because they clicked on a link in an email. An incident analysis has determined an…

The correct answer is E. Awareness training. Phishing attacks succeed by manipulating users into executing malicious payloads, making security awareness training the most effective control to address the human behavior root cause.

Enterprise Security Operations

Question

A company has gone through a round of phishing attacks. More than 200 users have had their workstation infected because they clicked on a link in an email. An incident analysis has determined an executable ran and compromised the administrator account on each workstation. Management is demanding the information security team prevent this from happening again. Which of the following would BEST prevent this from happening again?

Options

  • AAntivirus
  • BPatch management
  • CLog monitoring
  • DApplication whitelisting
  • EAwareness training

How the community answered

(19 responses)
  • B
    11% (2)
  • C
    5% (1)
  • D
    5% (1)
  • E
    79% (15)

Why each option

Phishing attacks succeed by manipulating users into executing malicious payloads, making security awareness training the most effective control to address the human behavior root cause.

AAntivirus

Antivirus may detect known malware signatures but can be bypassed by novel or obfuscated executables and does not prevent users from clicking phishing links.

BPatch management

Patch management reduces exploit risk against known vulnerabilities but does not prevent users from voluntarily executing malicious files delivered via phishing.

CLog monitoring

Log monitoring is a detective control and alerts after compromise has occurred; it does not prevent the phishing click from happening.

DApplication whitelisting

Application whitelisting prevents unauthorized executables but does not address the upstream human behavior that initiated the attack.

EAwareness trainingCorrect

The attack chain began with users clicking a link in a phishing email, a behavior that technical controls alone cannot fully prevent. Security awareness training directly addresses the root cause by educating users to recognize phishing attempts, reducing the likelihood of initial click-through and breaking the attack chain before any payload executes.

Concept tested: Security awareness training to counter phishing attacks

Source: https://www.cisa.gov/sites/default/files/publications/Phishing_Guidance_508C.pdf

Topics

#phishing prevention#security awareness training#endpoint protection#social engineering

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice