exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 65 discussion

Actual exam question from CompTIA's SY0-701
Question #: 65
Topic #: 1
[All SY0-701 Questions]

A security analyst and the management team are reviewing the organizational performance of a recent phishing campaign. The user click-through rate exceeded the acceptable risk threshold, and the management team wants to reduce the impact when a user clicks on a link in a phishing message. Which of the following should the analyst do?

  • A. Place posters around the office to raise awareness of common phishing activities.
  • B. Implement email security filters to prevent phishing emails from being delivered.
  • C. Update the EDR policies to block automatic execution of downloaded programs.
  • D. Create additional training for users to recognize the signs of phishing attempts.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SHADTECH123
Highly Voted 6 months, 2 weeks ago
Selected Answer: C
Updating the Endpoint Detection and Response (EDR) policies to block the automatic execution of downloaded programs helps to mitigate the risk by preventing malicious software from running even if a user clicks on a phishing link. This technical control directly addresses the potential consequences of a phishing attack by stopping harmful actions from taking place after the initial click, thus reducing the overall impact of the phishing campaign. While raising awareness (option A), implementing email security filters (option B), and creating additional training (option D) are all valuable preventive measures, they do not directly reduce the impact after a phishing link is clicked.
upvoted 29 times
43a41d4
4 months, 3 weeks ago
You're explanation is clean. Thank you.
upvoted 1 times
...
KO_
6 months, 1 week ago
Well explained
upvoted 2 times
...
...
barracouto
Highly Voted 9 months ago
C is the only one that that can actually be controlled by the analyst.. You can train as much as you want but that doesn't mean people listen... Source: all of us here using an exam dump after watching Messers course :)
upvoted 13 times
uday1985
8 months ago
interesting! how can you block fileless code executions ? When the last time you have encountered an actual exe in a phishing campaign? how about obfuscated scripts? this won't even stop clicking on link to steal information!
upvoted 3 times
...
...
tsummey
Most Recent 1 month, 4 weeks ago
Selected Answer: D
After reading the question a few times, I'm changing my answer to D. The first time around I didn't catch that a security analyst and management are assessing the organizational performance of a recent phishing campaign. This implies a phishing test. The best course of action based on too many user click-throughs is education.
upvoted 1 times
...
tsummey
1 month, 4 weeks ago
Selected Answer: B
The correct answer is B. EDR solutions like CrowdStrike do not provide direct link click-through protection. I’d like to better understand how modifying an EDR policy would prevent users from clicking on a phishing link without outright blocking all links they attempt to open. A Secure Email Gateway (SEG) / Email Security Gateway (ESG) is responsible for filtering malicious emails containing phishing URLs or attachments. Click-through protection is a key feature of ESGs like Proofpoint, Microsoft Defender for Office 365, and Mimecast. Admins can adjust filtering aggressiveness, and in this case, it’s likely that the current settings were too lenient, allowing phishing emails through. The best course of action is to modify ESG security filters to prevent these emails from reaching users. Ideally, this would be complemented by reviewing and enhancing security awareness training to reinforce phishing detection skills.
upvoted 1 times
MarysSon
2 weeks, 4 days ago
The question addresses what happens when a user DOES click on a phishing link. This is past the point of preventing the link from being clicked. EDR prevents the damage from taking effect. That's why C is the correct answer.
upvoted 1 times
...
...
Exam_Prep221
4 months ago
Selected Answer: C
They are talking about analyst So it'll be EDR
upvoted 1 times
...
darpanne
4 months ago
Selected Answer: C
C because Question is about when a user clicks on a link in a phishing message
upvoted 1 times
...
Spoudel001
4 months, 3 weeks ago
Selected Answer: B
By implementing advanced email security filters, the organization can significantly reduce the likelihood of phishing emails reaching employees in the first place.
upvoted 1 times
...
Bito808
6 months ago
Blocking automatic execution does not block all Phishing emails. Some Phishing emails try to redirect you or get you to contact a bad actor. This action is more focused on malware prevention, not necessarily Phishing attempts.
upvoted 1 times
...
Etc_Shadow28000
6 months, 2 weeks ago
Selected Answer: C
C. Update the EDR policies to block automatic execution of downloaded programs. While raising awareness, implementing email filters, and providing additional training are important measures, updating Endpoint Detection and Response (EDR) policies to block the automatic execution of downloaded programs directly addresses the issue of reducing the impact when a user clicks on a phishing link. This approach helps prevent malicious software from being executed on the user's system, thus mitigating potential harm. Therefore, the correct answer is: C. Update the EDR policies to block automatic execution of downloaded programs.
upvoted 4 times
...
Gigz_77
6 months, 3 weeks ago
Selected Answer: B
I think the best option is B. C. Phishing doesn't always come with executable files. It can redirect users to malicious pages which clones legitimate sites too when clicked on phishing links. D. This is an option too. But no matter how many trainings the organizations give to employees, they still fall for phishing emails
upvoted 2 times
...
Yurp
7 months, 1 week ago
Selected Answer: C
"reduce the impact when a user *clicks* on a link" read carefully, C is the only one that makes sense for someone who has already clicked a link.
upvoted 3 times
...
cri88
7 months, 2 weeks ago
Selected Answer: B
We can rule out: - C. Update the EDR policies to block automatic execution of downloaded programs. Given that the phishing link could lead to a serverless execution, which doesn't rely on downloading and executing a program on the user's machine, this answer would not fully address the risk. Or what if the link is a scam? Login details are still entered, so the impact when a user clicks on a link in a phishing message is still there. - A (Posters) and D (Training) focus on awareness and education, which are crucial for reducing click-through rates over time but do not directly prevent or mitigate the technical impact of a user clicking on a phishing link. So B is in my opinion the best answer.
upvoted 2 times
...
nap61
8 months ago
Selected Answer: C
"...wants to reduce the impact when a user clicks on a link in a phishing message..."
upvoted 4 times
...
EfaChux
8 months, 2 weeks ago
Selected Answer: D
Phishing is more of social engineering attack and most times does not involve download or running of malicious applications on the user system. More awareness is what is required to secure users against this kind of attacks
upvoted 3 times
...
dbrowndiver
8 months, 3 weeks ago
Selected Answer: C
Implementing EDR policy updates directly addresses the risk posed by phishing attacks by stopping malicious code from executing, thereby reducing the potential impact of users clicking on phishing links.
upvoted 2 times
...
MAKOhunter33333333
11 months ago
Selected Answer: C
Wants to reduce impact AFTER clinking the link. C is the only one that, B is preventive and happens before the user can even click the email
upvoted 3 times
...
AbdullahMohammad251
11 months ago
Selected Answer: C
Options A, B, and D represent proactive measures designed to mitigate the risk of exposure to phishing emails or clicking on their links. However, should a phishing email evade our security measures and be clicked by an employee, it becomes imperative to prevent any downloaded files from executing. Updating Endpoint Detection and Response (EDR) policies to block the automatic execution of downloaded programs would effectively thwart the attack.
upvoted 6 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago