200-201 Security Concepts Practice Question
A security analyst is reviewing the organization's defense-in-depth strategy. The analyst must recommend TWO controls that specifically reduce the risk of successful phishing attacks against employees. Which two controls should the analyst recommend? (Choose two.)
⚠ Common exam trap
The trap here is selecting network segmentation because it sounds like defense in depth, but it mitigates impact rather than preventing phishing success.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing email filtering that blocks messages with malicious attachments and links.
Email filtering and security awareness training are both direct anti-phishing controls. Filtering blocks malicious messages before delivery, while training helps users recognize and avoid phishing attempts that bypass filters. Together they form a layered defense. The other options address different threats such as web application attacks, data-at-rest protection, and lateral movement containment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implementing email filtering that blocks messages with malicious attachments and links.
Why this is correct
Email filtering inspects incoming messages and blocks those containing known malicious attachments, URLs, or sender reputations. This directly reduces the volume of phishing emails reaching user inboxes, lowering the chance of a successful attack. It is a preventive control that operates before the user interacts with the message, making it a core component of anti-phishing defense in depth.
- ✗
Configuring network segmentation to isolate the finance department from the rest of the network.
Why it's wrong here
Network segmentation limits lateral movement after a compromise, but it does not stop phishing emails from reaching users or prevent initial credential theft. It is a containment measure, not a preventive control against phishing. While it can reduce the impact of a successful phishing attack, the question asks for controls that reduce the risk of the attack succeeding in the first place.
- ✗
Deploying a web application firewall (WAF) to inspect HTTP traffic to the company's public website.
Why it's wrong here
A WAF protects web applications from attacks like SQL injection and cross-site scripting, but it does not inspect email or prevent phishing messages from reaching users. Phishing attacks typically arrive via email and may direct users to external sites, so a WAF on the company website would not address the initial delivery vector. This control is valuable for web security but not for reducing phishing risk.
- ✗
Enabling full-disk encryption on all employee laptops.
Why it's wrong here
Full-disk encryption protects data at rest if a device is lost or stolen, but it does not prevent phishing emails from being delivered or users from clicking malicious links. It addresses a different threat—physical device compromise—rather than social engineering. While important for overall security, it does not directly reduce the risk of a successful phishing attack.
- ✓
Conducting regular security awareness training that teaches employees to recognize phishing attempts.
Why this is correct
Security awareness training educates users on identifying phishing indicators such as mismatched sender addresses, urgent language, and suspicious links. It empowers employees to avoid falling for social engineering and to report suspicious emails. While not foolproof, it adds a human layer of defense that complements technical controls and is widely recommended to reduce phishing success rates.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.