An organization wants to reduce the risk from malicious macros in Microsoft Office documents received via email. Which defense is most effective for this specific threat?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because disabling macros by default and specifically blocking macros in files from internet origins (files with the Mark of the Web NTFS alternate data stream) directly targets the attack vector — malicious macro documents from email or web download. A is wrong because host-based firewalls control network traffic; they do not prevent macros from executing in Office documents already on the system.
Full explanation below image
Full Explanation
B is correct because disabling macros by default and specifically blocking macros in files from internet origins (files with the Mark of the Web NTFS alternate data stream) directly targets the attack vector — malicious macro documents from email or web download. A is wrong because host-based firewalls control network traffic; they do not prevent macros from executing in Office documents already on the system. C is wrong because switching office suites is not a realistic enterprise control and LibreOffice Basic macros can also be malicious. D is wrong because spam filters reduce phishing email volume but do not prevent macros from executing in emails that do pass through.