How to Reduce Impact When Users Click Phishing Links?

Security Operations / Phishing Mitigation

A security analyst and the management team are reviewing the organizational performance of a recent phishing campaign. The user click-through rate exceeded the acceptable risk threshold, and the management team wants to reduce the impact when a user clicks on a link in a phishing message. Which of the following should the analyst do?

  1. Place posters around the office to raise awareness of common phishing activities.
  2. Implement email security filters to prevent phishing emails from being delivered.
  3. Update the EDR policies to block automatic execution of downloaded programs. Source Reference Answer
  4. Create additional training for users to recognize the signs of phishing attempts.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you distinguish between preventative controls (training, email filters) and impact-reducing controls after a click. The trap is choosing user-focused options like training.

Learn why updating EDR policies is the correct way to reduce impact after a user clicks a phishing link. Community votes favor technical controls over awareness training for post-click protection.

Choosing D (additional training) is the most common mistake because it addresses the cause but not the immediate impact after a click. Training is proactive, not reactive.

Community Discussion (22 comments)

SHADTECH123 👍 29 Selected: C
Updating the Endpoint Detection and Response (EDR) policies to block the automatic execution of downloaded programs helps to mitigate the risk by preventing malicious software from running even if a user clicks on a phishing link. This technical control directly addresses the potential consequences of a phishing attack by stopping harmful actions from taking place after the initial click, thus reducing the overall impact of the phishing campaign. While raising awareness (option A), implementing email security filters (option B), and creating additional training (option D) are all valuable preventive measures, they do not directly reduce the impact after a phishing link is clicked.
barracouto 👍 13
C is the only one that that can actually be controlled by the analyst.. You can train as much as you want but that doesn't mean people listen... Source: all of us here using an exam dump after watching Messers course :)
tsummey 👍 1 Selected: D
After reading the question a few times, I'm changing my answer to D. The first time around I didn't catch that a security analyst and management are assessing the organizational performance of a recent phishing campaign. This implies a phishing test. The best course of action based on too many user click-throughs is education.
tsummey 👍 1 Selected: B
The correct answer is B. EDR solutions like CrowdStrike do not provide direct link click-through protection. I’d like to better understand how modifying an EDR policy would prevent users from clicking on a phishing link without outright blocking all links they attempt to open. A Secure Email Gateway (SEG) / Email Security Gateway (ESG) is responsible for filtering malicious emails containing phishing URLs or attachments. Click-through protection is a key feature of ESGs like Proofpoint, Microsoft Defender for Office 365, and Mimecast. Admins can adjust filtering aggressiveness, and in this case, it’s likely that the current settings were too lenient, allowing phishing emails through. The best course of action is to modify ESG security filters to prevent these emails from reaching users. Ideally, this would be complemented by reviewing and enhancing security awareness training to reinforce phishing detection skills.
Exam_Prep221 👍 1 Selected: C
They are talking about analyst So it'll be EDR
darpanne 👍 1 Selected: C
C because Question is about when a user clicks on a link in a phishing message
Spoudel001 👍 1 Selected: B
By implementing advanced email security filters, the organization can significantly reduce the likelihood of phishing emails reaching employees in the first place.
Bito808 👍 1
Blocking automatic execution does not block all Phishing emails. Some Phishing emails try to redirect you or get you to contact a bad actor. This action is more focused on malware prevention, not necessarily Phishing attempts.
Etc_Shadow28000 👍 4 Selected: C
C. Update the EDR policies to block automatic execution of downloaded programs. While raising awareness, implementing email filters, and providing additional training are important measures, updating Endpoint Detection and Response (EDR) policies to block the automatic execution of downloaded programs directly addresses the issue of reducing the impact when a user clicks on a phishing link. This approach helps prevent malicious software from being executed on the user's system, thus mitigating potential harm. Therefore, the correct answer is: C. Update the EDR policies to block automatic execution of downloaded programs.
Gigz_77 👍 2 Selected: B
I think the best option is B. C. Phishing doesn't always come with executable files. It can redirect users to malicious pages which clones legitimate sites too when clicked on phishing links. D. This is an option too. But no matter how many trainings the organizations give to employees, they still fall for phishing emails
Yurp 👍 3 Selected: C
"reduce the impact when a user clicks on a link" read carefully, C is the only one that makes sense for someone who has already clicked a link.
cri88 👍 2 Selected: B
We can rule out: - C. Update the EDR policies to block automatic execution of downloaded programs. Given that the phishing link could lead to a serverless execution, which doesn't rely on downloading and executing a program on the user's machine, this answer would not fully address the risk. Or what if the link is a scam? Login details are still entered, so the impact when a user clicks on a link in a phishing message is still there. - A (Posters) and D (Training) focus on awareness and education, which are crucial for reducing click-through rates over time but do not directly prevent or mitigate the technical impact of a user clicking on a phishing link. So B is in my opinion the best answer.
nap61 👍 4 Selected: C
"...wants to reduce the impact when a user clicks on a link in a phishing message..."
EfaChux 👍 3 Selected: D
Phishing is more of social engineering attack and most times does not involve download or running of malicious applications on the user system. More awareness is what is required to secure users against this kind of attacks
dbrowndiver 👍 2 Selected: C
Implementing EDR policy updates directly addresses the risk posed by phishing attacks by stopping malicious code from executing, thereby reducing the potential impact of users clicking on phishing links.
MAKOhunter33333333 👍 3 Selected: C
Wants to reduce impact AFTER clinking the link. C is the only one that, B is preventive and happens before the user can even click the email
AbdullahMohammad251 👍 6 Selected: C
Options A, B, and D represent proactive measures designed to mitigate the risk of exposure to phishing emails or clicking on their links. However, should a phishing email evade our security measures and be clicked by an employee, it becomes imperative to prevent any downloaded files from executing. Updating Endpoint Detection and Response (EDR) policies to block the automatic execution of downloaded programs would effectively thwart the attack.
networkmen 👍 4 Selected: C
If the question is "when the user clicks the link" the only right answer should be C. Everything else would not help after the user already clicked the link.
hasquaati 👍 2 Selected: C
Personally I would choose D, however even with training users are still clicking on phishing attempts. We would need an EDR policy to add to our security posture, remembering the idea of Security in Depth. We can't rely on one security strategy. I am going with C on this one.
AutoroTink 👍 2 Selected: C
Updating the EDR policy will reduce the impact of when a user clicks through, while D tries to prevent the user from clicking in the first place.
Jimmy1017 👍 1 Selected: D
I think it’s D because end users understanding best security practices is essential to protecting against security threats both old and new.
Xavierallen9711 👍 2 Selected: D
Additional training is key to lowering risks

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C directly addresses the scenario: the user has already clicked the link, so the goal is to minimize the resulting harm. Updating EDR policies to block automatic execution of downloaded programs ensures that even if a user clicks, malicious payloads cannot run. As community comment [1] notes, this technical control prevents malicious software from executing and mitigates the impact after the initial click. Comment [6] emphasizes that any other option would not help after the click, and comment [7] highlights the importance of reading the exact wording 'when a user clicks'.

Exam Strategy

Focus on the phrase 'when a user clicks' to identify that only a technical control like EDR policy can reduce impact after the click. Eliminate options that are purely preventative, such as training or email filtering, since they aim to prevent the click from happening in the first place.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide