A security analyst and the management team are reviewing the organizational performance of a recent phishing campaign. The user click-through rate exceeded the acceptable risk threshold, and the management team wants to reduce the impact when a user clicks on a link in a phishing message. Which of the following should the analyst do?
Choose an answer
Tap an option to check your answer.
Correct answer: Update the EDR policies to block automatic execution of downloaded programs..
Why this is the answer
The correct answer is to update EDR policies to block automatic execution of downloaded programs. While the click-through rate was high, indicating users clicked malicious links, this action focuses on reducing the impact of those clicks, as requested by management. Blocking automatic execution prevents malware from running even if a user downloads it, thus mitigating the immediate threat. Placing posters and creating additional training are both valuable for preventing clicks in the future, but they don't address the immediate impact of a user having already clicked. Implementing email security filters is also a preventative measure, aiming to stop phishing emails from reaching the inbox at all, rather than mitigating the consequences of a successful click-through.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed