200-201 exam dumps

200-201 practice question 111 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 111

Select 3

A cybersecurity analyst at a company receives reports of phishing emails bypassing the organization's email security filters. The emails include malicious links and attachments. Which actions should the analyst take to enhance email content filtering and reduce the threat of phishing attacks?

  1. A

    Implement keyword-based filtering to block emails containing suspicious words like 'urgent' or 'free'.

  2. B

    Enable attachment scanning to detect and block malicious file types in incoming emails.

  3. C

    Establish a policy to whitelist all emails from known domains to avoid disruptions.

  4. D

    Configure URL filtering to block emails containing links to suspicious or known malicious websites.

  5. E

    Disable email filtering temporarily to investigate the issue manually.

Show answer and explanation

Correct answers: A, B, D

Explanation

The correct actions to enhance email content filtering involve implementing multiple layers of security. Keyword-based filtering, attachment scanning, and URL filtering are proactive measures to identify and block phishing emails. Whitelisting all known domains or disabling filtering are not effective or secure solutions to address phishing risks.

  • A. Correct.

    Implementing keyword-based filtering is a common practice to identify phishing attempts, as phishing emails often use specific words or phrases to entice users to act quickly.

  • B. Correct.

    Enabling attachment scanning helps detect and block malicious file types, such as executable files or macros, which are frequently used in phishing attacks.

  • C. Incorrect.

    Whitelisting all emails from known domains can introduce significant security risks, as attackers can spoof these domains to bypass filtering mechanisms.

  • D. Correct.

    Configuring URL filtering is an effective method to block emails with links to malicious or suspicious websites, reducing the risk of phishing.

  • E. Incorrect.

    Disabling email filtering temporarily is not a recommended action, as it could expose the organization to a higher volume of malicious emails during the investigation.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam