🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

During an internal investigation, you learn that several developers received text messages impersonating the company's AWS help desk. The SMS claimed their console sessions had expired and urged them to tap a shortened URL to re-authenticate; two developers complied and divulged credentials. With minimal cost and without adding new infrastructure, which single control would most effectively reduce the likelihood of future smishing attacks succeeding?

  • Deploy AWS WAF rules to block all inbound HTTP requests that include URL-shortening domains referenced in the fraudulent texts.

  • Require every employee to use SMS-based multi-factor authentication (MFA) for AWS Management Console access.

  • Enable Amazon GuardDuty DNS threat detection and automatically quarantine any EC2 instance that contacts known phishing domains.

  • Implement recurring security awareness training that incorporates simulated smishing exercises and just-in-time coaching for recipients.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot