nerdexam
CompTIA

CAS-001 · Question #21

A company is evaluating a new marketing strategy involving the use of social networking sites to reach its customers. The marketing director wants to be able to report important company news…

The correct answer is B. Malware infection D. Phishing attacks F. Social engineering attacks. Using social networking for business introduces risks tied to the nature of those platforms - exposure to malware, deceptive links, and manipulation by adversaries. The three major risks relate directly to how attackers exploit social media users.

Enterprise Security

Question

A company is evaluating a new marketing strategy involving the use of social networking sites to reach its customers. The marketing director wants to be able to report important company news, product updates, and special promotions on the social websites. After an initial and successful pilot period, other departments want to use the social websites to post their updates as well. The Chief Information Officer (CIO) has asked the company security administrator to document three negative security impacts of allowing IT staff to post work related information on such websites. Which of the following are the major risks the security administrator should report back to the CIO? (Select THREE).

Options

  • ABrute force attacks
  • BMalware infection
  • CDDOS attacks
  • DPhishing attacks
  • ESQL injection attacks
  • FSocial engineering attacks

How the community answered

(56 responses)
  • A
    5% (3)
  • B
    89% (50)
  • C
    4% (2)
  • E
    2% (1)

Why each option

Using social networking for business introduces risks tied to the nature of those platforms - exposure to malware, deceptive links, and manipulation by adversaries. The three major risks relate directly to how attackers exploit social media users.

ABrute force attacks

Brute force attacks target authentication systems directly and are not a risk introduced by employees posting on social networking sites.

BMalware infectionCorrect

Social networking sites are common malware distribution vectors through malicious links, attachments, or drive-by downloads embedded in posts and messages, making malware infection a direct risk when staff interact with these platforms for business.

CDDOS attacks

DDoS attacks target network availability and are launched against servers or infrastructure, not a consequence of employees using social media for business communications.

DPhishing attacksCorrect

Phishing attacks are highly prevalent on social media because attackers can craft convincing fake messages or pages that impersonate brands, colleagues, or promotions, tricking employees into surrendering credentials or clicking malicious links.

ESQL injection attacks

SQL injection attacks exploit web application input fields and are unrelated to the act of staff posting company information on social networking platforms.

FSocial engineering attacksCorrect

Social engineering attacks are especially effective on social networking sites because adversaries can gather personal and professional information from public profiles to craft targeted manipulation attempts against employees.

Concept tested: Social media security risks for organizations

Source: https://www.cisa.gov/sites/default/files/publications/Social_Networking_Sites.pdf

Topics

#social media security#malware#phishing#social engineering

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice