Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A security analyst notices that a phishing campaign is targeting employees with emails that appear to be from the company's IT support team. The emails contain a link to a website that mimics the corporate password reset portal. Which of the following controls would be MOST effective in preventing users from reaching the malicious website, assuming the link uses HTTPS?

⚠ Common exam trap

A common mix-up: candidates assume HTTPS encryption makes URL filtering impossible, but the exam expects you to know that web proxies can inspect or block HTTPS traffic using SSL/TLS decryption or domain-based filtering, making URL filtering still effective.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement a URL filtering policy on the company's web proxy.

A URL filtering policy on the company's web proxy is the most effective control because it can block access to the malicious website based on its domain, category, or reputation, regardless of whether the link uses HTTPS. Since the proxy can perform SSL/TLS inspection (decrypting the HTTPS traffic) or use domain reputation lists, it prevents users from even reaching the phishing site. This directly addresses the core issue of users navigating to a known or suspicious URL.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement a URL filtering policy on the company's web proxy.

    Why this is correct

    Implementing URL filtering on the corporate web proxy is a preventive technical control that actively blocks access to known malicious, phishing, or lookalike domains at the network layer. The proxy inspects the requested URL and domain against real-time reputation feeds and policy categories; if the destination matches a threat intel blocklist, the connection is terminated before the browser loads the page. Because it operates in-line on HTTP and HTTPS traffic (using SNI/TLS inspection or DNS resolution), this control disrupts the phishing kill chain regardless of how the link was delivered, including via webmail, social media, or messaging apps. It does not rely on user judgment, making it a more consistent and automated safeguard than awareness training.

  • Deploy an email security gateway that performs sandboxing of attachments.

    Why it's wrong here

    Sandboxing in an email security gateway is designed to detonate and observe email attachments for malicious behaviors, such as macro execution or exploit attempts, not to analyze or block hyperlinks embedded in the message body. Although some email gateways offer separate URL reputation scanning, the specific capability described here—attachment sandboxing—would leave the link untouched and still clickable by the user. Moreover, even if a sandbox identified a malicious attachment, it would not prevent a user from clicking a phishing URL that leads to a credential-harvesting page; the link itself is harmless until clicked, and sandboxing never sees that interaction. Thus, this control addresses a different attack vector (malicious file payloads) and fails to mitigate the actual phishing link threat.

    When this WOULD be correct

    An email security gateway with sandboxing would be correct if the phishing campaign included malicious attachments (e.g., PDFs or Office documents with embedded macros) that need to be detonated in a safe environment to detect threats.

  • Enable multi-factor authentication on all corporate accounts.

    Why it's wrong here

    Incorrect. Multi-factor authentication mitigates credential theft if a user's password is phished, but it does not prevent the user from clicking the link and visiting the malicious website, which is the immediate risk to stop.

    When this WOULD be correct

    In a scenario where a phishing campaign successfully harvests credentials and attackers attempt to log in to corporate accounts, enabling MFA would be the most effective control to block unauthorized access even if credentials are stolen.

  • Conduct a security awareness training session on phishing.

    Why it's wrong here

    Incorrect. Training empowers users to recognize phishing attempts, but it is not a technical control that actively blocks the website. It relies on user discretion and may not be as consistently effective as a technical block.

    When this WOULD be correct

    A question asks: 'Which control is MOST effective in reducing the likelihood that employees will fall for a phishing campaign targeting password reset credentials?' In that context, training directly addresses user susceptibility.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Implement a URL filtering policy on the company's web proxy.Correct answer

Why this is correct

Implementing URL filtering on the corporate web proxy is a preventive technical control that actively blocks access to known malicious, phishing, or lookalike domains at the network layer. The proxy inspects the requested URL and domain against real-time reputation feeds and policy categories; if the destination matches a threat intel blocklist, the connection is terminated before the browser loads the page. Because it operates in-line on HTTP and HTTPS traffic (using SNI/TLS inspection or DNS resolution), this control disrupts the phishing kill chain regardless of how the link was delivered, including via webmail, social media, or messaging apps. It does not rely on user judgment, making it a more consistent and automated safeguard than awareness training.

Deploy an email security gateway that performs sandboxing of attachments.Wrong answer — click to see why

Why this is wrong here

The question specifies that the link uses HTTPS, so sandboxing attachments is irrelevant because the threat is a link in the email body, not an attachment. Email sandboxing analyzes file attachments for malware, not URLs.

★ When this WOULD be the correct answer

An email security gateway with sandboxing would be correct if the phishing campaign included malicious attachments (e.g., PDFs or Office documents with embedded macros) that need to be detonated in a safe environment to detect threats.

Why candidates choose this

Candidates may think that any email security solution can block phishing, but sandboxing specifically targets attachments, not links. They might confuse sandboxing with URL analysis or general email filtering capabilities.

Enable multi-factor authentication on all corporate accounts.Wrong answer — click to see why

Why this is wrong here

Multi-factor authentication (MFA) protects against credential theft after a user reaches a malicious site, but it does not prevent users from initially accessing the site. The question asks for a control to prevent reaching the malicious website, not to mitigate the impact of credential compromise.

★ When this WOULD be the correct answer

In a scenario where a phishing campaign successfully harvests credentials and attackers attempt to log in to corporate accounts, enabling MFA would be the most effective control to block unauthorized access even if credentials are stolen.

Why candidates choose this

Candidates may think MFA is a universal security solution and overlook that it addresses post-compromise risks rather than preventing initial access to malicious sites.

Conduct a security awareness training session on phishing.Wrong answer — click to see why

Why this is wrong here

Security awareness training educates users to recognize phishing, but it does not prevent users from reaching the malicious website if they click the link. The question asks for a control that prevents access to the site, not user behavior.

★ When this WOULD be the correct answer

A question asks: 'Which control is MOST effective in reducing the likelihood that employees will fall for a phishing campaign targeting password reset credentials?' In that context, training directly addresses user susceptibility.

Why candidates choose this

Candidates often overvalue training as a catch-all security measure, forgetting that technical controls like URL filtering block access regardless of user decisions.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.