CAS-005 · Question #160
A Chief Information Security Officer assigns a team to create malicious communications for a social engineering campaign. The purpose of this campaign is to determine the number of employees who…
The correct answer is A. Phishing. The question describes a social engineering campaign involving malicious communications to test employee susceptibility and asks for training to reduce click rates in the future.
Question
A Chief Information Security Officer assigns a team to create malicious communications for a social engineering campaign. The purpose of this campaign is to determine the number of employees who might be susceptible to social engineering attacks. The following is a summary report from a previous campaign:
Which of the following training modules would reduce click rates in the future?
Options
- APhishing
- BWhaling
- CSmishing
- DTailgating
How the community answered
(30 responses)- A93% (28)
- B3% (1)
- C3% (1)
Why each option
The question describes a social engineering campaign involving malicious communications to test employee susceptibility and asks for training to reduce click rates in the future.
Phishing is a type of social engineering attack that attempts to trick individuals into revealing sensitive information, clicking malicious links, or downloading malware, typically via fraudulent emails or messages. Training modules on phishing would directly educate employees on how to identify and avoid such malicious communications, thereby reducing click rates in future campaigns.
Whaling is a specific type of phishing attack targeting high-profile individuals within an organization; while related, a general phishing training module is more broadly applicable to reducing click rates among all employees.
Smishing is phishing conducted via SMS text messages, which is a specific vector, whereas 'malicious communications' typically encompasses email-based attacks that fall under general phishing.
Tailgating is a physical security breach where an unauthorized person follows an authorized person into a restricted area; it is not a digital social engineering attack related to click rates.
Concept tested: Social engineering awareness training
Source: https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/anti-phishing-policies-overview?view=o365-worldwide
Community Discussion
No community discussion yet for this question.