112-52 · Question #16
What is the best way to mitigate social engineering attacks in an organization?
The correct answer is B. Conduct regular employee security awareness training. Regular employee security awareness training (B) is the most effective mitigation because social engineering attacks exploit human behavior - not technical vulnerabilities. Attackers use tactics like phishing, pretexting, and impersonation to manipulate people into revealing cred
Question
What is the best way to mitigate social engineering attacks in an organization?
Options
- AImplement stronger passwords
- BConduct regular employee security awareness training
- CInstall antivirus software on all machines
- DUse encryption for sensitive data
How the community answered
(40 responses)- A3% (1)
- B95% (38)
- D3% (1)
Explanation
Regular employee security awareness training (B) is the most effective mitigation because social engineering attacks exploit human behavior - not technical vulnerabilities. Attackers use tactics like phishing, pretexting, and impersonation to manipulate people into revealing credentials or granting access, so training employees to recognize and resist these tactics addresses the root cause directly.
Why the distractors fall short:
- A (Stronger passwords) helps against brute-force attacks but doesn't stop an employee from willingly handing over their credentials to a convincing impersonator.
- C (Antivirus software) detects malware, not manipulation - a socially engineered employee can bypass technical controls entirely.
- D (Encryption) protects data in transit/at rest but is irrelevant if an attacker tricks someone into voluntarily disclosing it.
Memory tip: Think of social engineering as hacking humans, not systems. The only countermeasure that matches the attack vector is training the humans - "fight social with social."
Topics
Community Discussion
No community discussion yet for this question.