A security report shows that during a two-week test period, 80% of employees unwittingly disclosed their SSO credentials when accessing an external website. The organization purposely created the website to simulate a cost-free password complexity test. Which of the following would best help reduce the number of visits to similar websites in the future?
Choose an answer
Tap an option to check your answer.
Correct answer: Introduce a campaign to recognize phishing attempts..
Why this is the answer
The scenario describes a simulated phishing attack where employees disclosed credentials. The best way to reduce future occurrences of this specific issue is to educate employees on how to identify and avoid phishing attempts. A campaign to recognize phishing attempts directly addresses the root cause: employee susceptibility to social engineering. Blocking all outbound traffic from the intranet is overly restrictive and would severely impact productivity, as legitimate external websites are necessary for business operations. Restricting internet access for only those employees who disclosed credentials is a punitive measure that doesn't address the broader organizational vulnerability and could harm morale. Implementing a deny list of websites is a reactive measure; new malicious websites constantly emerge, making it impractical to block every potential phishing site. Education is a proactive and sustainable solution.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed