CAS-001 · Question #21
A company is evaluating a new marketing strategy involving the use of social networking sites to reach its customers. The marketing director wants to be able to report important company news…
The correct answer is B. Malware infection D. Phishing attacks F. Social engineering attacks. Using social networking for business introduces risks tied to the nature of those platforms - exposure to malware, deceptive links, and manipulation by adversaries. The three major risks relate directly to how attackers exploit social media users.
Question
A company is evaluating a new marketing strategy involving the use of social networking sites to reach its customers. The marketing director wants to be able to report important company news, product updates, and special promotions on the social websites. After an initial and successful pilot period, other departments want to use the social websites to post their updates as well. The Chief Information Officer (CIO) has asked the company security administrator to document three negative security impacts of allowing IT staff to post work related information on such websites. Which of the following are the major risks the security administrator should report back to the CIO? (Select THREE).
Options
- ABrute force attacks
- BMalware infection
- CDDOS attacks
- DPhishing attacks
- ESQL injection attacks
- FSocial engineering attacks
How the community answered
(56 responses)- A5% (3)
- B89% (50)
- C4% (2)
- E2% (1)
Why each option
Using social networking for business introduces risks tied to the nature of those platforms - exposure to malware, deceptive links, and manipulation by adversaries. The three major risks relate directly to how attackers exploit social media users.
Brute force attacks target authentication systems directly and are not a risk introduced by employees posting on social networking sites.
Social networking sites are common malware distribution vectors through malicious links, attachments, or drive-by downloads embedded in posts and messages, making malware infection a direct risk when staff interact with these platforms for business.
DDoS attacks target network availability and are launched against servers or infrastructure, not a consequence of employees using social media for business communications.
Phishing attacks are highly prevalent on social media because attackers can craft convincing fake messages or pages that impersonate brands, colleagues, or promotions, tricking employees into surrendering credentials or clicking malicious links.
SQL injection attacks exploit web application input fields and are unrelated to the act of staff posting company information on social networking platforms.
Social engineering attacks are especially effective on social networking sites because adversaries can gather personal and professional information from public profiles to craft targeted manipulation attempts against employees.
Concept tested: Social media security risks for organizations
Source: https://www.cisa.gov/sites/default/files/publications/Social_Networking_Sites.pdf
Topics
Community Discussion
No community discussion yet for this question.