Certified Information Systems Security Professional CISSP · Free Practice Question Medium
Question 72
You are the Chief Information Security Officer (CISO) of a multinational corporation. Your company has been seeing an increase in phishing attempts targeting your employees. The range of attacks varies from simple phishing attempts sent out to thousands of employees, hoping a few might fall for it, to more sophisticated spear-phishing campaigns targeting key individuals in the company. What is the most effective strategy to protect your employees and the company from these types of phishing attacks?
- A Implement two-factor authentication across all systems and services.
- B Establish a robust email filtering system that flags and isolates potential phishing emails.
- C Develop and implement a comprehensive anti-phishing strategy that includes employee training, robust email filtering systems, regular updates and patching, and two-factor authentication for all systems.
- D Regularly update and patch all software, systems, and services to fix any potential vulnerabilities.
Reveal correct answer
Correct answer: C
Explanation
The correct answer: Developing and implementing a comprehensive anti-phishing strategy that includes employee training, robust email filtering systems, regular updates and patching, and two-factor authentication for all systems is the most effective strategy to protect your employees and the company from phishing attacks. Phishing is an attack that relies on human error, and employee training is critical. Employees should be educated on how to identify and report phishing attempts. A robust email filtering system will automatically detect and isolate potential phishing emails, reducing the risk of an employee inadvertently clicking on a malicious link. Regular updates and patching will ensure that potential software vulnerabilities that could be exploited are fixed. Two-factor authentication adds an extra layer of security by requiring an additional verification step, making it harder for attackers to gain unauthorized access. The incorrect answers: Implementing two-factor authentication across all systems and services is a good practice and can provide an additional layer of security, but it does not address the need for employee training to identify phishing attempts or the use of robust email filtering systems to automatically flag potential threats. Regularly updating and patching all software, systems, and services to fix any potential vulnerabilities is also important, but it focuses solely on system vulnerabilities and doesn't directly address the issue of phishing, which primarily exploits human error. Establishing a robust email filtering system that flags and isolates potential phishing emails is a part of a good anti-phishing strategy, but it needs to be combined with other measures such as two-factor authentication, employee training, and regular updates and patching to be truly effective.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
