nerdexam
EC-Council

312-50V13 · Question #598

A company recently experienced a debilitating social engineering attack that led to substantial identity theft. An inquiry found that the employee inadvertently provided critical information during…

The correct answer is A. Conduct comprehensive training sessions for employees on various social engineering. Comprehensive training sessions for employees on various social engineering tactics would be the most successful countermeasure to prevent identity theft resulting from an employee inadvertently providing critical information during a phone conversation.

Submitted by salim_om· Mar 6, 2026Social Engineering

Question

A company recently experienced a debilitating social engineering attack that led to substantial identity theft. An inquiry found that the employee inadvertently provided critical information during an innocuous phone conversation. Considering the specific guidelines issued by the company to thwart social engineering attacks, which countermeasure would have been the most successful in averting the incident?

Options

  • AConduct comprehensive training sessions for employees on various social engineering
  • BImplement a well-documented change management process for modifications related to hardware
  • CAdopt a robust software policy that restricts the installation of unauthorized applications.
  • DReinforce physical security measures to limit access to sensitive zones within the company

How the community answered

(58 responses)
  • A
    81% (47)
  • B
    10% (6)
  • C
    2% (1)
  • D
    7% (4)

Why each option

Comprehensive training sessions for employees on various social engineering tactics would be the most successful countermeasure to prevent identity theft resulting from an employee inadvertently providing critical information during a phone conversation.

AConduct comprehensive training sessions for employees on various social engineeringCorrect

Social engineering attacks, especially those involving phone conversations, rely on manipulating human psychology and exploiting a lack of awareness. Comprehensive training sessions educate employees about common social engineering tactics, how to identify suspicious requests, and company policies for information disclosure, directly equipping them to resist such attacks and prevent inadvertent information sharing.

BImplement a well-documented change management process for modifications related to hardware

A change management process applies to system modifications and would not directly prevent an employee from being tricked into revealing sensitive information through social engineering.

CAdopt a robust software policy that restricts the installation of unauthorized applications.

A robust software policy restricts unauthorized application installation but does not address the human element of social engineering attacks conducted via phone calls.

DReinforce physical security measures to limit access to sensitive zones within the company

Reinforcing physical security measures limits access to physical locations but does not protect against social engineering attacks conducted remotely, such as over the phone.

Concept tested: Social engineering countermeasures and employee training

Source: https://learn.microsoft.com/en-us/training/modules/security-best-practices-identify-protect-against-social-engineering/

Topics

#Social engineering#Employee awareness#Security awareness training#Identity theft prevention

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice