An employee clicks a malicious link in an email that appears to be from the company's Chief Executive Officer. The employee's computer is infected with ransomware that encrypts the company's files. Which of the following is the most effective way for the company to prevent similar incidents in the future?
Choose an answer
Tap an option to check your answer.
Correct answer: Security awareness training.
Why this is the answer
Security awareness training is the most effective solution because it directly addresses the human element, which was exploited in this phishing attack. Training employees to recognize malicious links, verify sender identities, and understand the risks of ransomware empowers them to avoid similar incidents. While database encryption protects data at rest, it wouldn't prevent the initial infection or file encryption by ransomware. Segmentation isolates network segments, which could limit the spread of ransomware but wouldn't prevent the initial compromise. Reporting suspicious emails is a good practice, but without prior training, employees might not identify the email as suspicious in the first place.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed