An organization wants to mitigate the risk of targeted spear-phishing attacks leading to credential theft. Which layered defense strategy provides the MOST comprehensive protection?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- ACorrect: training helps users recognize targeted lures, while MFA stops a stolen password alone from granting access, covering both the human and credential layers.
- BFirewalls and EDR help against malware, but a convincing phishing page that harvests credentials can bypass both.
- CSegmentation limits lateral movement after a compromise but does not stop credentials from being phished in the first place.
- DComplexity and rotation rules do not help once a user types the password into a phishing page, and frequent rotation encourages weaker patterns.