Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsHard
A large enterprise is experiencing a significant increase in phishing attempts targeting its employees. These emails often contain malicious links or attachments. The company has already implemented email filtering and user awareness training. To further strengthen its defenses against this specific attack vector, which additional security control would provide the most immediate and effective improvement?
- AUtilizing a Security Orchestration, Automation, and Response (SOAR) platform.
- BImplementing a robust Data Loss Prevention (DLP) solution.
- CEnabling Multi-Factor Authentication (MFA) for all user accounts.
- DDeploying a Network Access Control (NAC) system.
Show answer & explanationAnswer & explanation
Correct answer: C. Enabling Multi-Factor Authentication (MFA) for all user accounts.
While email filtering and training reduce phishing attempts, MFA directly counters the most common outcome of successful phishing: credential compromise. Even if a user falls for a phishing scam and enters their password, MFA prevents an attacker from logging in without the second factor.
Why the other options are wrong
- A. SOAR automates incident response but doesn't prevent the initial credential compromise from phishing.
- B. DLP prevents data exfiltration, which is a consequence, not a direct prevention of phishing-induced credential theft.
- D. NAC controls device access to the network, which doesn't directly prevent an attacker from using stolen credentials.
Multi-Factor Authentication (MFA) against Phishing
MFA significantly mitigates the risk of successful phishing attacks by requiring an additional verification factor beyond a password, making stolen credentials less useful to attackers.
- Protects against credential stuffing and stolen passwords.
- Adds a layer of security even if phishing is successful.
- Considered a critical control for account security.
Memory trick: Beyond the lure, a second lock stops the catch.