nerdexam
CompTIA

CAS-002 · Question #185

A security manager is developing new policies and procedures. Which of the following is a best practice in end user security?

The correct answer is B. A training program that is consistent, ongoing, and relevant. A consistent, ongoing, and relevant training program is the foundational best practice for end-user security because it directly addresses the human element.

Enterprise Security

Question

A security manager is developing new policies and procedures. Which of the following is a best practice in end user security?

Options

  • AEmployee identity badges and physical access controls to ensure only staff are allowed
  • BA training program that is consistent, ongoing, and relevant.
  • CAccess controls to prevent end users from gaining access to confidential data.
  • DAccess controls for computer systems and networks with two-factor authentication.

How the community answered

(51 responses)
  • A
    2% (1)
  • B
    86% (44)
  • C
    4% (2)
  • D
    8% (4)

Why each option

A consistent, ongoing, and relevant training program is the foundational best practice for end-user security because it directly addresses the human element.

AEmployee identity badges and physical access controls to ensure only staff are allowed

Physical access controls and identity badges protect facilities but are physical security controls, not end-user security awareness practices.

BA training program that is consistent, ongoing, and relevant.Correct

Security awareness training that is consistent and regularly updated educates users about current threats such as phishing and social engineering, which are the primary attack vectors targeting end users. Making training relevant to employees' actual roles increases retention and behavioral change, reducing the risk of uninformed or negligent actions that technical controls alone cannot fully address.

CAccess controls to prevent end users from gaining access to confidential data.

Access controls that restrict data access are technical preventive controls, not end-user security education or awareness measures.

DAccess controls for computer systems and networks with two-factor authentication.

Two-factor authentication is a technical access control mechanism, not an end-user security best practice in the awareness or behavioral training sense.

Concept tested: End-user security awareness training as primary control

Source: https://csrc.nist.gov/publications/detail/sp/800-50/final

Topics

#security awareness training#end user security#security culture#human factors

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice