QuestionQ71

Incident Response Processes

An insider dispersed multiple USB flash drives containing zero-day malware throughout a company HQ building. Many employees connected the USB flash drives to their workstations. An attacker was able to access endpoints externally, steal user credentials, and exfiltrate confidential information from internal web resources. Which two actions will prevent these types of security incidents in the future?

Choose two
  • A Automate security alerts on connected USB flash drives to workstations.
  • B Provide security awareness training and block usage of external drives.
  • C Deploy antivirus software on employee workstations to detect malicious software.
  • D Encrypt traffic from employee workstations to internal web services.
  • E Deploy MFA authentication to prevent unauthorized access to critical assets.
Explanation

Security awareness training helps personnel recognize the risk of unknown removable media, while blocking external drives prevents untrusted USB devices from executing or delivering malware on workstations. MFA requires an additional authenticator beyond a stolen password, preventing an attacker who has obtained credentials from accessing critical assets. CISA states that MFA helps prevent unauthorized access even when credentials are compromised.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!