nerdexam
CompTIA

SY0-501 · Question #458

A company has noticed multiple instances of proprietary information on public websites. It has also observed an increase in the number of email messages sent to random employees containing malicious…

The correct answer is C. Block access to personal email on corporate systems E. Update corporate policy to prohibit access to social media websites. This question tests the ability to identify administrative and technical controls that reduce phishing attack surface. The correct answers address two key vectors: corporate systems being used to access personal email and social media exposure that enables spear-phishing…

Submitted by stefanr· Mar 4, 2026Security program management and oversight

Question

A company has noticed multiple instances of proprietary information on public websites. It has also observed an increase in the number of email messages sent to random employees containing malicious links and PDFs. Which of the following changes should the company make to reduce the risks associated with phishing attacks? (Select TWO)

Options

  • AInstall an additional firewall
  • BImplement a redundant email server
  • CBlock access to personal email on corporate systems
  • DUpdate the X.509 certificates on the corporate email server
  • EUpdate corporate policy to prohibit access to social media websites
  • FReview access violation on the file server

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    13% (3)
  • C
    78% (18)
  • D
    4% (1)

Why each option

This question tests the ability to identify administrative and technical controls that reduce phishing attack surface. The correct answers address two key vectors: corporate systems being used to access personal email and social media exposure that enables spear-phishing reconnaissance.

AInstall an additional firewall

An additional firewall addresses network perimeter security but does not specifically mitigate phishing attacks, which rely on user interaction with malicious content rather than direct network intrusion.

BImplement a redundant email server

A redundant email server improves availability and fault tolerance but does nothing to filter or reduce malicious emails reaching employees, making it irrelevant to phishing risk reduction.

CBlock access to personal email on corporate systemsCorrect

Blocking personal email on corporate systems removes a significant phishing vector, as attackers frequently target personal email accounts with malicious links and attachments that employees may open on corporate devices, bypassing corporate email filtering controls entirely.

DUpdate the X.509 certificates on the corporate email server

Updating X.509 certificates on the corporate email server relates to email encryption and authentication integrity, but does not prevent employees from receiving or clicking on phishing emails.

EUpdate corporate policy to prohibit access to social media websitesCorrect

Prohibiting access to social media websites reduces the reconnaissance data available to attackers for crafting targeted spear-phishing campaigns, and also prevents employees from inadvertently posting proprietary information that has already been observed on public websites.

FReview access violation on the file server

Reviewing file server access violations is a detective control useful for identifying a breach after it occurs, but it does not proactively reduce the risk of employees falling victim to phishing attacks.

Concept tested: Reducing phishing attack surface through policy controls

Source: https://learn.microsoft.com/en-us/security/operations/incident-response-playbook-phishing

Topics

#phishing#social media policy#email security#data leakage

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice