200-201 Question 110
Single answerA security analyst at your organization has configured an email content filtering solution to block emails containing specific keywords associated with phishing attempts. Despite this, employees are still receiving phishing emails that bypass the filter. What is the most effective additional action the analyst can take to improve the email content filtering system?
- A
Enable attachment scanning and block emails with suspicious attachment types.
- B
Reduce the sensitivity of the content filtering system to allow more emails through.
- C
Whitelist all internal email addresses to bypass the content filtering system.
- D
Integrate the content filtering system with a threat intelligence feed to update keyword lists dynamically.
Show answer and explanation
Correct answer: D
Explanation
The integration of a content filtering system with a threat intelligence feed ensures that the system stays up to date with the latest phishing tactics and keywords. This dynamic updating process improves the system's ability to detect and block phishing emails that may otherwise bypass static keyword-based filtering, making it the most effective additional action to enhance email security.
- A. Incorrect.
Attachment scanning is useful for detecting malicious files but does not directly address phishing emails that bypass keyword-based filtering.
- B. Incorrect.
Reducing the sensitivity of the content filtering system would increase the likelihood of phishing emails reaching users, making this an ineffective solution.
- C. Incorrect.
Whitelisting internal email addresses can create a significant vulnerability if attackers successfully spoof internal addresses, bypassing the filter entirely.
- D. Correct.
Integrating with a threat intelligence feed allows the content filtering system to dynamically update its keyword and rule sets based on known and emerging threats, improving its effectiveness against phishing emails.