nerdexam
CompTIA

CAS-002 · Question #556

A company is evaluating a new marketing strategy involving the use of social networking sites to reach its customers. The marketing director wants to be able to report important company news…

The correct answer is B. Malware infection D. Phishing attacks F. Social engineering attacks. Using social networking sites for business communications introduces malware, phishing, and social engineering risks because public posts expose company and employee information to adversaries.

Research and Analysis

Question

A company is evaluating a new marketing strategy involving the use of social networking sites to reach its customers. The marketing director wants to be able to report important company news, product updates, and special promotions on the social websites. After an initial and successful pilot period, other departments want to use the social websites to post their updates as well. The Chief Information Officer (CIO) has asked the company security administrator to document three negative security impacts of allowing IT staff to post work related information on such websites. Which of the following are the major risks the security administrator should report back to the CIO? (Select THREE).

Options

  • ABrute force attacks
  • BMalware infection
  • CDDOS attacks
  • DPhishing attacks
  • ESQL injection attacks
  • FSocial engineering attacks

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    84% (26)
  • C
    3% (1)
  • E
    10% (3)

Why each option

Using social networking sites for business communications introduces malware, phishing, and social engineering risks because public posts expose company and employee information to adversaries.

ABrute force attacks

Brute force attacks target authentication systems directly and are not a risk introduced specifically by employees posting on social networking sites.

BMalware infectionCorrect

Social networking platforms can be vectors for malware through malicious links, drive-by downloads, or compromised third-party apps that employees interact with while accessing company-related content.

CDDOS attacks

DDoS attacks are infrastructure-level volumetric attacks that are not caused or enabled by a company's social media posting activity.

DPhishing attacksCorrect

Information disclosed on social media - such as employee roles, product names, and project details - enables attackers to craft highly targeted spear-phishing emails or messages against employees and customers.

ESQL injection attacks

SQL injection is a web application input-validation vulnerability that is unrelated to the act of posting information on social networking platforms.

FSocial engineering attacksCorrect

Publicly posted details about company structure, personnel, and operations give social engineers the reconnaissance data needed to manipulate employees or partners into disclosing sensitive information or performing unauthorized actions.

Concept tested: Social media security risks - malware, phishing, social engineering

Source: https://www.cisa.gov/sites/default/files/publications/Social_Media_Cybersecurity_Tip_Sheet_Final.pdf

Topics

#social networking risk#phishing#social engineering#malware infection

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice