312-50 exam dumps

312-50 practice question 13 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 13

Single answer▪ Information Security Controls

A company has suffered several incidents in which employees clicked phishing links and entered credentials into fake login pages. Management asks the security team to recommend the MOST effective information security control to reduce the likelihood of credential compromise from this specific attack path while minimizing disruption to normal business operations. Which control should the team recommend first?

  1. A

    Implement multifactor authentication (MFA) for all remote and cloud-based logins

  2. B

    Deploy full-disk encryption on all employee laptops

  3. C

    Install a host-based intrusion detection system (HIDS) on user workstations

  4. D

    Increase password complexity requirements from 12 to 20 characters

Show answer and explanation

Correct answer: A

Explanation

The scenario focuses on phishing-based credential theft, so the best answer is the control that most directly interrupts that attack chain. MFA is a preventive access control that significantly reduces successful account takeover when passwords are exposed. This aligns with widely accepted guidance from NIST and CISA, which emphasize MFA as a key mitigation for identity-based attacks. By contrast, full-disk encryption protects confidentiality of local data on lost devices, HIDS mainly provides detection rather than primary prevention of stolen-credential misuse, and password complexity does not stop users from entering valid credentials into phishing sites. In real environments, the strongest approach is layered: deploy MFA, combine it with user awareness training, anti-phishing protections, conditional access, and where possible phishing-resistant methods such as FIDO2/WebAuthn.

  • A. Correct.

    Correct. MFA is a strong preventive access control that directly reduces the impact of stolen usernames and passwords obtained through phishing. Even if a user enters credentials into a fake page, the attacker is less likely to successfully authenticate without the second factor. This is one of the most practical and widely recommended controls for mitigating credential-based attacks against remote access, SaaS platforms, VPNs, and webmail.

  • B. Incorrect.

    Incorrect. Full-disk encryption is an important preventive control for protecting data at rest if a device is lost or stolen, but it does not meaningfully stop an attacker from using phished credentials against online services. Someone might choose this because it is a strong security control in general, but it does not address the stated attack path.

  • C. Incorrect.

    Incorrect. A HIDS can help detect suspicious activity on endpoints, such as malware execution or unauthorized changes, but it is not the most effective first control for preventing credential misuse after phishing. It is more of a detective control and may provide visibility after compromise rather than directly blocking fraudulent logins.

  • D. Incorrect.

    Incorrect. Stronger passwords can improve resistance to brute-force and password-guessing attacks, but they do not adequately address real-time phishing where users voluntarily submit valid credentials to attackers. This is a common misconception: password complexity helps against some threats, but phishing-resistant access controls are more effective for this scenario.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam