Courseiva
hardMultiple Choice

FC0-U71 Practice Question: A small real estate office with 12 employees has…

A small real estate office with 12 employees has been using the same network setup for five years. Employees use both company-issued laptops and personal smartphones to access email and client listings. Last week, an employee clicked a link in a phishing email, which led to a ransomware infection on the company file server. The server was encrypted, and the attackers demanded a ransom. The office had no backups; all client data and contracts were lost. The office manager wants to prevent such incidents in the future. Which of the following should be the FIRST security measure implemented, considering the root cause of the breach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mandate security awareness training for all employees, focusing on phishing identification

The root cause was a phishing email that tricked an employee. While technical controls like antivirus (A), next-generation firewall (B), and full-disk encryption (C) are valuable, they do not address the human factor. Security awareness training (D) educates users to recognize phishing attempts, reducing the likelihood of similar incidents. Without training, other controls can be bypassed. Option D is the most direct and effective first step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Install antivirus software on all company laptops and personal devices

    Why it's wrong here

    Antivirus on endpoints scans local files and processes, but the ransomware encrypted the file server, and signature-based detection frequently misses new ransomware variants. It would be correct as a baseline control against known malware on laptops and personal devices, not as the first measure addressing phishing-driven server compromise.

  • ✗

    Deploy a next-generation firewall with intrusion prevention

    Why it's wrong here

    A next-generation firewall inspects network traffic, but the phishing link was clicked by a user and the ransomware executed on the file server, so perimeter inspection does not address the root cause. It would be correct for blocking malicious inbound connections or command-and-control traffic at the network boundary.

  • ✗

    Enable full-disk encryption on all company laptops

    Why it's wrong here

    Full-disk encryption protects data at rest on a stolen laptop; it cannot stop a phishing link executing ransomware on a file server, nor restore lost client data. It would be correct for meeting confidentiality requirements on mobile devices that may be physically lost or stolen.

  • ✓

    Mandate security awareness training for all employees, focusing on phishing identification

    Why this is correct

    The phishing click was the root cause, so mandating security awareness training addresses how the ransomware entered. Teaching employees to recognise and report phishing emails prevents recurrence, satisfying the requirement to fix the underlying human vulnerability first.

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.