312-50V12 · Question #189
A company recently experienced a debilitating social engineering attack that led to substantial identity theft. An inquiry found that the employee inadvertently provided critical information during an
The correct answer is A. Conduct comprehensive training sessions for employees on various social engineering. The incident involved an employee inadvertently providing critical information during a phone conversation due to a social engineering attack. The most effective countermeasure would directly address the human factor and the specific attack vector.
Question
Options
- AConduct comprehensive training sessions for employees on various social engineering
- BImplement a well-documented change management process for modifications related to hardware
- CAdopt a robust software policy that restricts the installation of unauthorized applications.
- DReinforce physical security measures to limit access to sensitive zones within the company
How the community answered
(38 responses)- A84% (32)
- B8% (3)
- C5% (2)
- D3% (1)
Why each option
The incident involved an employee inadvertently providing critical information during a phone conversation due to a social engineering attack. The most effective countermeasure would directly address the human factor and the specific attack vector.
Comprehensive training educates employees on how to identify and respond to social engineering tactics, such as vishing (voice phishing), which directly addresses the scenario where an employee inadvertently provides information over the phone. This empowers employees to recognize suspicious requests and avoid disclosing sensitive data, aligning with company guidelines to thwart such attacks.
Change management processes are crucial for managing system modifications but do not directly prevent employees from being tricked into divulging information during a social engineering phone call.
A robust software policy prevents unauthorized application installations but does not mitigate the risk of an employee being socially engineered over the phone.
Physical security measures protect against unauthorized physical access to facilities, which is unrelated to a social engineering attack conducted via a phone conversation.
Concept tested: Social Engineering Prevention Training
Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/security-awareness-training?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.