CAS-003 · Question #908
An organization's email filler is an ineffective control and as a result employees have been constantly receiving phishing emails. As part of a security incident investigation a security analyst…
The correct answer is A. EDR and DLP. The incident evidence maps directly to two control gaps. EDR (Endpoint Detection and Response) would have captured detailed endpoint telemetry - which uncategorized URLs were visited, what the downloaded .doc file did (e.g., macro execution, process spawning, lateral movement)…
Question
Options
- AEDR and DLP
- BDAM and MFA
- CHIPS and application whitelisting
- DFIM and antivirus
How the community answered
(29 responses)- A62% (18)
- B10% (3)
- C7% (2)
- D21% (6)
Explanation
The incident evidence maps directly to two control gaps. EDR (Endpoint Detection and Response) would have captured detailed endpoint telemetry - which uncategorized URLs were visited, what the downloaded .doc file did (e.g., macro execution, process spawning, lateral movement), and what processes were running - giving the analyst the forensic depth needed to establish root cause. DLP (Data Loss Prevention) addresses the most critical finding: files being uploaded to an unknown collaboration site, which indicates potential data exfiltration. DLP can inspect outbound traffic, classify data, and block or alert on unauthorized transfers. Option B (DAM/MFA) targets database monitoring and authentication, not endpoint or exfiltration activity. Option C (HIPS/whitelisting) is more preventive than investigative. Option D (FIM/antivirus) detects file changes and known malware but lacks the behavioral coverage and data-exfiltration visibility of EDR and DLP combined.
Topics
Community Discussion
No community discussion yet for this question.