nerdexam
CompTIA

CAS-002 · Question #187

A small customer focused bank with implemented least privilege principles, is concerned about the possibility of branch staff unintentionally aiding fraud in their day to day interactions with…

The correct answer is B. Awareness training. Security awareness training is the most targeted control for reducing the risk of staff unintentionally enabling fraud through personal customer relationships.

Enterprise Security

Question

A small customer focused bank with implemented least privilege principles, is concerned about the possibility of branch staff unintentionally aiding fraud in their day to day interactions with customers. Bank staff has been encouraged to build friendships with customers to make the banking experience feel more personal. The security and risk team have decided that a policy needs to be implemented across all branches to address the risk. Which of the following BEST addresses the security and risk team's concerns?

Options

  • AInformation disclosure policy
  • BAwareness training
  • CJob rotation
  • DSeparation of duties

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    81% (22)
  • C
    4% (1)
  • D
    7% (2)

Why each option

Security awareness training is the most targeted control for reducing the risk of staff unintentionally enabling fraud through personal customer relationships.

AInformation disclosure policy

An information disclosure policy establishes rules about what can be shared, but without training, staff may not recognize when a customer interaction crosses policy boundaries through social manipulation.

BAwareness trainingCorrect

Awareness training directly addresses the behavioral risk by educating branch staff on social engineering tactics, appropriate information boundaries, and how personal relationships can be exploited by fraudsters. Because the threat is unintentional and relationship-driven rather than malicious insider activity, changing staff behavior through education is more effective than structural or technical controls.

CJob rotation

Job rotation mitigates risks from knowledge concentration and insider collusion but does not address the social dynamics of personal customer relationships being exploited for fraud.

DSeparation of duties

Separation of duties divides tasks among multiple individuals to prevent single-person fraud but does not address the risk of unintentional disclosure or assistance caused by staff-customer friendships.

Concept tested: Awareness training to counter social engineering in customer-facing roles

Source: https://csrc.nist.gov/publications/detail/sp/800-50/final

Topics

#social engineering#awareness training#insider fraud#least privilege

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice