312-50V9 · Question #611
You went to great lengths to install all the necessary technologies to prevent hacking attacks, such as expensive firewalls, antivirus software, anti-spam systems and intrusion detection/prevention…
The correct answer is A. Untrained staff or ignorant computer users who inadvertently become the weakest link in your security chain. The 'weakest link' in network security refers to human users, whose susceptibility to social engineering and mistakes bypasses even the most robust technical controls.
Question
You went to great lengths to install all the necessary technologies to prevent hacking attacks, such as expensive firewalls, antivirus software, anti-spam systems and intrusion detection/prevention tools in your company's network. You have configured the most secure policies and tightened every device on your network. You are confident that hackers will never be able to gain access to your network with complex security system in place. Your peer, Peter Smith who works at the same department disagrees with you. He says even the best network security technologies cannot prevent hackers gaining access to the network because of presence of "weakest link" in the security chain. What is Peter Smith talking about?
Options
- AUntrained staff or ignorant computer users who inadvertently become the weakest link in your security chain
- B"zero-day" exploits are the weakest link in the security chain since the IDS will not be able to detect
- C"Polymorphic viruses" are the weakest link in the security chain since the Anti-Virus scanners will
- DContinuous Spam e-mails cannot be blocked by your security system since spammers use different
How the community answered
(38 responses)- A92% (35)
- B5% (2)
- D3% (1)
Why each option
The 'weakest link' in network security refers to human users, whose susceptibility to social engineering and mistakes bypasses even the most robust technical controls.
No technical security control can fully compensate for untrained or unaware users who can be manipulated through social engineering tactics such as phishing, pretexting, or baiting. Attackers routinely target humans because it is far easier to trick a person into revealing credentials or clicking a malicious link than to defeat a properly configured firewall or IDS.
Zero-day exploits are a serious technical threat but are not universally described as the single weakest link; they are specific unpatched vulnerabilities, not a systemic human failure point.
Polymorphic viruses evade signature-based antivirus scanning, but modern heuristic and behavioral detection reduces this risk and they do not represent the primary systemic weakness across all organizations.
Spam filtering technology can significantly reduce but not fully eliminate spam, yet spam volume is a nuisance problem rather than the foundational systemic weakness referred to as the 'weakest link.'
Concept tested: Human factor as weakest link in security
Source: https://csrc.nist.gov/publications/detail/sp/800-50/final
Topics
Community Discussion
No community discussion yet for this question.