CAS-005 · Question #354
An incident response team completed recovery from offline backup for several workstations. The workstations were subjected to a ransomware attack after users fell victim to a spear-phishing…
The correct answer is D. What measurable user behaviors were exhibited that contributed to the compromise? E. Which technical controls, if implemented, would provide defense when user training fails? What measurable user behaviors were exhibited that contributed to the compromise? During the lessons-learned phase, it's important to analyze the specific user behaviors that led to the successful spear-phishing attack, even after a robust training program. This could involve…
Question
An incident response team completed recovery from offline backup for several workstations. The workstations were subjected to a ransomware attack after users fell victim to a spear-phishing campaign, despite a robust training program. Which of the following questions should be considered during the lessons-learned phase to most likely reduce the risk of reoccurrence? (Choose two.)
Options
- AAre there opportunities for legal recourse against the originators of the spear-phishing campaign?
- BWhat internal and external stakeholders need to be notified of the breach?
- CWhich methods can be implemented to increase speed of offline backup recovery?
- DWhat measurable user behaviors were exhibited that contributed to the compromise?
- EWhich technical controls, if implemented, would provide defense when user training fails?
- FWhich user roles are most often targeted by spear phishing attacks?
How the community answered
(25 responses)- A20% (5)
- B4% (1)
- C12% (3)
- D56% (14)
- F8% (2)
Explanation
What measurable user behaviors were exhibited that contributed to the compromise? During the lessons-learned phase, it's important to analyze the specific user behaviors that led to the successful spear-phishing attack, even after a robust training program. This could involve understanding patterns such as clicking on suspicious links, failing to verify emails, or not reporting unusual activity. By identifying these behaviors, the organization can target specific areas for improvement in training or behavior modification. Which technical controls, if implemented, would provide defense when user training fails? Since users fell victim to the spear-phishing attack despite training, it's critical to implement technical controls that can provide an additional layer of defense. This may include email filtering to block phishing attempts, multi-factor authentication (MFA), endpoint detection and response (EDR) tools, and sandboxing for suspicious attachments. These controls will help prevent or mitigate attacks when training alone is insufficient.
Community Discussion
No community discussion yet for this question.