312-50V13 · Question #598
A company recently experienced a debilitating social engineering attack that led to substantial identity theft. An inquiry found that the employee inadvertently provided critical information during…
The correct answer is A. Conduct comprehensive training sessions for employees on various social engineering. Comprehensive training sessions for employees on various social engineering tactics would be the most successful countermeasure to prevent identity theft resulting from an employee inadvertently providing critical information during a phone conversation.
Question
Options
- AConduct comprehensive training sessions for employees on various social engineering
- BImplement a well-documented change management process for modifications related to hardware
- CAdopt a robust software policy that restricts the installation of unauthorized applications.
- DReinforce physical security measures to limit access to sensitive zones within the company
How the community answered
(58 responses)- A81% (47)
- B10% (6)
- C2% (1)
- D7% (4)
Why each option
Comprehensive training sessions for employees on various social engineering tactics would be the most successful countermeasure to prevent identity theft resulting from an employee inadvertently providing critical information during a phone conversation.
Social engineering attacks, especially those involving phone conversations, rely on manipulating human psychology and exploiting a lack of awareness. Comprehensive training sessions educate employees about common social engineering tactics, how to identify suspicious requests, and company policies for information disclosure, directly equipping them to resist such attacks and prevent inadvertent information sharing.
A change management process applies to system modifications and would not directly prevent an employee from being tricked into revealing sensitive information through social engineering.
A robust software policy restricts unauthorized application installation but does not address the human element of social engineering attacks conducted via phone calls.
Reinforcing physical security measures limits access to physical locations but does not protect against social engineering attacks conducted remotely, such as over the phone.
Concept tested: Social engineering countermeasures and employee training
Source: https://learn.microsoft.com/en-us/training/modules/security-best-practices-identify-protect-against-social-engineering/
Topics
Community Discussion
No community discussion yet for this question.