An incident response team determines that the root cause of a breach was a phishing email that delivered a malicious document. After remediation, what specific control should be added to the Preparation phase update to prevent recurrence?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because the root cause was a phishing email with a malicious attachment; the directly relevant preventive controls are email security (attachment detonation in sandbox, anti-phishing filters) and user training to recognize phishing. A is wrong because network IDS signatures detect network-based threats; they would not have prevented a phishing email from being opened.
Full explanation below image
Full Explanation
B is correct because the root cause was a phishing email with a malicious attachment; the directly relevant preventive controls are email security (attachment detonation in sandbox, anti-phishing filters) and user training to recognize phishing. A is wrong because network IDS signatures detect network-based threats; they would not have prevented a phishing email from being opened. C is wrong because rebuilding all workstations is a remediation action, not a preventive control for future phishing attacks. D is wrong because firewall throughput is a performance concern; email-borne attacks are not blocked by higher-throughput firewalls.