How to Reduce Impact When Users Click Phishing Links?
A security analyst and the management team are reviewing the organizational performance of a recent phishing campaign. The user click-through rate exceeded the acceptable risk threshold, and the management team wants to reduce the impact when a user clicks on a link in a phishing message. Which of the following should the analyst do?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you distinguish between preventative controls (training, email filters) and impact-reducing controls after a click. The trap is choosing user-focused options like training.
Learn why updating EDR policies is the correct way to reduce impact after a user clicks a phishing link. Community votes favor technical controls over awareness training for post-click protection.
Choosing D (additional training) is the most common mistake because it addresses the cause but not the immediate impact after a click. Training is proactive, not reactive.
Community Discussion (22 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option C directly addresses the scenario: the user has already clicked the link, so the goal is to minimize the resulting harm. Updating EDR policies to block automatic execution of downloaded programs ensures that even if a user clicks, malicious payloads cannot run. As community comment [1] notes, this technical control prevents malicious software from executing and mitigates the impact after the initial click. Comment [6] emphasizes that any other option would not help after the click, and comment [7] highlights the importance of reading the exact wording 'when a user clicks'.Exam Strategy
Focus on the phrase 'when a user clicks' to identify that only a technical control like EDR policy can reduce impact after the click. Eliminate options that are purely preventative, such as training or email filtering, since they aim to prevent the click from happening in the first place.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →