CAS-003 · Question #349
A company has gone through a round of phishing attacks. More than 200 users have had their workstation infected because they clicked on a link in an email. An incident analysis has determined an…
The correct answer is E. Awareness training. Phishing attacks succeed by manipulating users into executing malicious payloads, making security awareness training the most effective control to address the human behavior root cause.
Question
A company has gone through a round of phishing attacks. More than 200 users have had their workstation infected because they clicked on a link in an email. An incident analysis has determined an executable ran and compromised the administrator account on each workstation. Management is demanding the information security team prevent this from happening again. Which of the following would BEST prevent this from happening again?
Options
- AAntivirus
- BPatch management
- CLog monitoring
- DApplication whitelisting
- EAwareness training
How the community answered
(19 responses)- B11% (2)
- C5% (1)
- D5% (1)
- E79% (15)
Why each option
Phishing attacks succeed by manipulating users into executing malicious payloads, making security awareness training the most effective control to address the human behavior root cause.
Antivirus may detect known malware signatures but can be bypassed by novel or obfuscated executables and does not prevent users from clicking phishing links.
Patch management reduces exploit risk against known vulnerabilities but does not prevent users from voluntarily executing malicious files delivered via phishing.
Log monitoring is a detective control and alerts after compromise has occurred; it does not prevent the phishing click from happening.
Application whitelisting prevents unauthorized executables but does not address the upstream human behavior that initiated the attack.
The attack chain began with users clicking a link in a phishing email, a behavior that technical controls alone cannot fully prevent. Security awareness training directly addresses the root cause by educating users to recognize phishing attempts, reducing the likelihood of initial click-through and breaking the attack chain before any payload executes.
Concept tested: Security awareness training to counter phishing attacks
Source: https://www.cisa.gov/sites/default/files/publications/Phishing_Guidance_508C.pdf
Topics
Community Discussion
No community discussion yet for this question.