CISA · Question #166
An organization saves confidential information in a file with password protection, and the file is placed in a shared folder. An attacker has stolen this information by obtaining the password through
The correct answer is B. Security awareness programs for employees. The root cause of this incident was social engineering - an attacker manipulated a person into revealing a password. The most effective countermeasure is security awareness training, which equips employees to recognize and resist social engineering tactics. Technical controls lik
Question
An organization saves confidential information in a file with password protection, and the file is placed in a shared folder. An attacker has stolen this information by obtaining the password through social engineering. Implementing which of the following would BEST enable the organization to prevent this type of incident in the future?
Options
- AMulti-factor authentication (MFA)
- BSecurity awareness programs for employees
- CAccess history log review by the business manager
- DFile encryption along with password protection
How the community answered
(38 responses)- A5% (2)
- B74% (28)
- C8% (3)
- D13% (5)
Explanation
The root cause of this incident was social engineering - an attacker manipulated a person into revealing a password. The most effective countermeasure is security awareness training, which equips employees to recognize and resist social engineering tactics. Technical controls like MFA (A) reduce the risk of credential compromise but do not address the human vulnerability exploited here - and social engineering can also be used to bypass MFA. Access log review (C) is a detective control, not preventive. File encryption with password protection (D) still relies on a secret that can be socially engineered.
Topics
Community Discussion
No community discussion yet for this question.