nerdexam
CompTIA

CAS-003 · Question #908

An organization's email filler is an ineffective control and as a result employees have been constantly receiving phishing emails. As part of a security incident investigation a security analyst…

The correct answer is A. EDR and DLP. The incident evidence maps directly to two control gaps. EDR (Endpoint Detection and Response) would have captured detailed endpoint telemetry - which uncategorized URLs were visited, what the downloaded .doc file did (e.g., macro execution, process spawning, lateral movement)…

Enterprise Security Operations

Question

An organization's email filler is an ineffective control and as a result employees have been constantly receiving phishing emails. As part of a security incident investigation a security analyst identifies the following: 1. An employee was working remotely when the security alert was triggered 2. An employee visited a number of uncategorized internet sites 3. A doc file was downloaded 4. A number of files were uploaded to an unknown collaboration site Which of the following controls would provide the security analyst with more data to identify the root cause of the issue and protect the organization's information during future incidents?

Options

  • AEDR and DLP
  • BDAM and MFA
  • CHIPS and application whitelisting
  • DFIM and antivirus

How the community answered

(29 responses)
  • A
    62% (18)
  • B
    10% (3)
  • C
    7% (2)
  • D
    21% (6)

Explanation

The incident evidence maps directly to two control gaps. EDR (Endpoint Detection and Response) would have captured detailed endpoint telemetry - which uncategorized URLs were visited, what the downloaded .doc file did (e.g., macro execution, process spawning, lateral movement), and what processes were running - giving the analyst the forensic depth needed to establish root cause. DLP (Data Loss Prevention) addresses the most critical finding: files being uploaded to an unknown collaboration site, which indicates potential data exfiltration. DLP can inspect outbound traffic, classify data, and block or alert on unauthorized transfers. Option B (DAM/MFA) targets database monitoring and authentication, not endpoint or exfiltration activity. Option C (HIPS/whitelisting) is more preventive than investigative. Option D (FIM/antivirus) detects file changes and known malware but lacks the behavioral coverage and data-exfiltration visibility of EDR and DLP combined.

Topics

#EDR#DLP#phishing investigation#incident response

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice