Which attack is hardest to mitigate with technology?
Which of the following attacks is the most difficult to mitigate with technology?
Community Votes
80% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the distinction between technical vulnerabilities and human-centric threats, highlighting that while tools can filter emails, they cannot eliminate the psychological manipulation inherent in phishing.
Phishing relies on social engineering, making it the most difficult security threat to fully mitigate through technological means alone compared to technical vulnerabilities like SQL injection or malware.
Candidates often select SQL Injection (C) because it requires complex code exploitation, failing to recognize that modern WAFs and input validation are highly effective technical mitigations for SQLi, whereas human behavior remains unpredictable.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Phishing is primarily a social engineering attack that exploits human psychology rather than software flaws. While email filtering, DMARC, and multi-factor authentication reduce risk, they cannot completely neutralize the element of deception when a user is actively manipulated into bypassing controls. Consequently, technology alone has diminishing returns against sophisticated phishing campaigns.Why the Other Options Are Wrong
Ransomware (A) and Backdoors (B) are largely addressed by endpoint protection, patch management, and network segmentation. SQL Injection (C) is a web application vulnerability effectively mitigated by Web Application Firewalls (WAF), parameterized queries, and input validation. These three have clear, mature technological defense mechanisms, unlike the human variable in phishing.Community Comment Notes
The community consensus strongly favors Phishing due to the 'human factor' argument. Comment [2] correctly notes that education is required alongside technology, implying technology is insufficient alone. Comment [3]'s vote for SQL Injection represents a common misconception where candidates overestimate the difficulty of SQLi mitigation relative to the unpredictability of human error.Official Reference
Exam Strategy
Always distinguish between attacks targeting systems (technical) and attacks targeting people (social). When asked about 'technology' limitations, look for options involving human interaction or decision-making.
Related Analysis
Practice All SK0-005 Questions
Access 135 questions with complete answers and detailed explanations.
View Full SK0-005 Practice Test →