A security team has been alerted to a flood of incoming emails that have various subject lines and are addressed to multiple email inboxes. Each email contains a URL shortener link that is redirecting to a dead domain. Which of the following is the best step for the security team to take?
Choose an answer
Tap an option to check your answer.
Correct answer: Block the URL shortener domain in the web proxy..
Why this is the answer
Blocking the URL shortener domain in the web proxy is the most effective immediate step because it prevents users from accessing the malicious links, regardless of the specific dead domain they redirect to. This proactive measure stops the threat at the network edge. Creating a blocklist for all subject lines is impractical due to the variety and would likely miss new variations. Sending the dead domain to a DNS sinkhole is useful for analysis and preventing future access to that specific domain, but it doesn't address the current threat of users clicking the URL shortener. Quarantining all emails is disruptive and may not be sustainable for a flood, and notifying all employees without preventing access still leaves a window for accidental clicks.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed