nerdexam
CompTIA

220-802 · Question #501

A company would like to prevent commonly known social engineering risks. Which of the following would help mitigate these risks?

The correct answer is A. Annual security training. Social engineering targets human behavior rather than technical vulnerabilities, so annual security awareness training is the most effective mitigation because it teaches employees to recognize and resist manipulation tactics.

Hardware and network troubleshooting

Question

A company would like to prevent commonly known social engineering risks. Which of the following would help mitigate these risks?

Options

  • AAnnual security training
  • BInstall new switches
  • CReview security policies
  • DRequire 180 day password expiration

How the community answered

(49 responses)
  • A
    90% (44)
  • B
    6% (3)
  • C
    2% (1)
  • D
    2% (1)

Why each option

Social engineering targets human behavior rather than technical vulnerabilities, so annual security awareness training is the most effective mitigation because it teaches employees to recognize and resist manipulation tactics.

AAnnual security trainingCorrect

Security awareness training educates employees on common social engineering techniques such as phishing, pretexting, and tailgating, enabling them to identify and report attacks before damage occurs. Regular training keeps staff current with evolving threat tactics and reinforces a security-conscious culture, which is the primary defense against human-targeted attacks.

BInstall new switches

Installing new switches improves network infrastructure but does nothing to address the human vulnerabilities that social engineering exploits.

CReview security policies

Reviewing security policies updates documentation but does not directly change employee behavior or awareness of social engineering tactics.

DRequire 180 day password expiration

A 180-day password expiration policy addresses credential security but does not help employees recognize or resist social engineering attempts.

Concept tested: Security awareness training as social engineering mitigation

Source: https://www.cisa.gov/topics/cybersecurity-best-practices/social-engineering

Topics

#social engineering#security awareness training#risk mitigation#security policy

Community Discussion

No community discussion yet for this question.

Full 220-802 Practice