nerdexam
CompTIA

SY0-701 · Question #595

An employee clicks a malicious link in an email that appears to be from the company's Chief Executive Officer. The employee's computer is infected with ransomware that encrypts the company's files…

The correct answer is A. Security awareness training. Security awareness training (A) is correct because the root cause of this incident was human error - an employee was deceived by a phishing email impersonating the CEO (a "spear phishing" or "whaling" attack). Training employees to recognize suspicious emails, verify sender…

Submitted by ricky.ec· Mar 6, 2026Threats, vulnerabilities, and mitigations

Question

An employee clicks a malicious link in an email that appears to be from the company's Chief Executive Officer. The employee's computer is infected with ransomware that encrypts the company's files. Which of the following is the most effective way for the company to prevent similar incidents in the future?

Options

  • ASecurity awareness training
  • BDatabase encryption
  • CSegmentation
  • DReporting suspicious emails

How the community answered

(29 responses)
  • A
    72% (21)
  • B
    7% (2)
  • C
    3% (1)
  • D
    17% (5)

Explanation

Security awareness training (A) is correct because the root cause of this incident was human error - an employee was deceived by a phishing email impersonating the CEO (a "spear phishing" or "whaling" attack). Training employees to recognize suspicious emails, verify sender identities, and avoid clicking unknown links directly addresses the attack vector.

Database encryption (B) protects data at rest but does nothing to prevent an employee from clicking a malicious link - the ransomware would still execute and encrypt files regardless. Segmentation (C) limits lateral movement after a breach and can reduce the blast radius, but it doesn't prevent the initial infection from occurring. Reporting suspicious emails (D) is a component of awareness training, not a standalone preventive control - and it's reactive rather than proactive; the click already happened before reporting would occur.

Memory tip: When a question involves an employee being tricked into doing something harmful, the answer almost always involves people-focused controls (training, policies) because technology alone can't fix a human behavior problem. Think: "You can't patch humans with firewalls."

Topics

#Security awareness training#Phishing#Social engineering#Ransomware prevention

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice