220-802 · Question #501
A company would like to prevent commonly known social engineering risks. Which of the following would help mitigate these risks?
The correct answer is A. Annual security training. Social engineering targets human behavior rather than technical vulnerabilities, so annual security awareness training is the most effective mitigation because it teaches employees to recognize and resist manipulation tactics.
Question
A company would like to prevent commonly known social engineering risks. Which of the following would help mitigate these risks?
Options
- AAnnual security training
- BInstall new switches
- CReview security policies
- DRequire 180 day password expiration
How the community answered
(49 responses)- A90% (44)
- B6% (3)
- C2% (1)
- D2% (1)
Why each option
Social engineering targets human behavior rather than technical vulnerabilities, so annual security awareness training is the most effective mitigation because it teaches employees to recognize and resist manipulation tactics.
Security awareness training educates employees on common social engineering techniques such as phishing, pretexting, and tailgating, enabling them to identify and report attacks before damage occurs. Regular training keeps staff current with evolving threat tactics and reinforces a security-conscious culture, which is the primary defense against human-targeted attacks.
Installing new switches improves network infrastructure but does nothing to address the human vulnerabilities that social engineering exploits.
Reviewing security policies updates documentation but does not directly change employee behavior or awareness of social engineering tactics.
A 180-day password expiration policy addresses credential security but does not help employees recognize or resist social engineering attempts.
Concept tested: Security awareness training as social engineering mitigation
Source: https://www.cisa.gov/topics/cybersecurity-best-practices/social-engineering
Topics
Community Discussion
No community discussion yet for this question.