A company is concerned about employees unintentionally introducing malware into the network. The company identified fifty employees who clicked on a link embedded in an email sent by the internal IT department. Which of the following should the company implement to best improve its security posture?
Choose an answer
Tap an option to check your answer.
Correct answer: Social engineering training.
Why this is the answer
Social engineering training is the best option because it directly addresses the root cause of the problem: employees falling for a social engineering tactic (phishing). Training would educate employees on how to identify and avoid such attacks, reducing the likelihood of future incidents. SPF (Sender Policy Framework) configuration helps prevent email spoofing but wouldn't stop employees from clicking malicious links in emails that appear legitimate. A simulated phishing campaign is a good tool for testing the effectiveness of training and identifying vulnerable employees, but it's not a solution in itself for improving the overall security posture. Insider threat awareness focuses on malicious actions by employees, whereas this scenario describes unintentional actions due to a lack of awareness.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed