CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium
A security analyst is conducting a post-incident review for a successful phishing attack that compromised several user accounts. As part of the 'lessons learned' report, the analyst needs to identify the root cause to prevent future occurrences. The investigation revealed that users clicked malicious links and entered credentials on fake login pages. Which of the following would MOST likely be identified as the root cause?
- AAbsence of a robust email filtering solution.
- BLack of multi-factor authentication (MFA) on critical systems.
- CInsufficient user security awareness training.
- DDelay in patching the email server vulnerability.
Show answer & explanationAnswer & explanation
Correct answer: C. Insufficient user security awareness training.
While MFA and email filtering are crucial controls, the direct cause of users 'clicking malicious links and entering credentials' points to a failure in user judgment and understanding of phishing tactics. This strongly indicates insufficient user security awareness training as the root cause that allowed the initial compromise, even if other technical controls could have mitigated its impact.
Why the other options are wrong
- A. Robust email filtering would ideally block phishing emails, but its absence is a control gap, not the root cause of users interacting with the malicious content.
- B. MFA would have prevented account compromise AFTER credential theft but doesn't address the root cause of users falling for the phishing scam itself.
- D. A delay in patching an email server vulnerability could be a root cause for server compromise, but not directly for users falling for a phishing link in an email that reached them.
Root Cause Analysis (Phishing)
The process of identifying the fundamental reason or underlying factor that, if removed or corrected, would prevent a phishing incident from recurring, often pointing to human factors or control gaps.
- Goes beyond immediate symptoms.
- For phishing, often reveals human vulnerability or control failure.
- Aims to implement effective, long-term preventative measures.
Memory trick: Phishing: The 'Human' is the 'Root' when they 'Click' and 'Type'.