nerdexam
Isaca

CISA · Question #166

An organization saves confidential information in a file with password protection, and the file is placed in a shared folder. An attacker has stolen this information by obtaining the password through

The correct answer is B. Security awareness programs for employees. The root cause of this incident was social engineering - an attacker manipulated a person into revealing a password. The most effective countermeasure is security awareness training, which equips employees to recognize and resist social engineering tactics. Technical controls lik

Submitted by salim_om· Apr 18, 2026Protection of Information Assets

Question

An organization saves confidential information in a file with password protection, and the file is placed in a shared folder. An attacker has stolen this information by obtaining the password through social engineering. Implementing which of the following would BEST enable the organization to prevent this type of incident in the future?

Options

  • AMulti-factor authentication (MFA)
  • BSecurity awareness programs for employees
  • CAccess history log review by the business manager
  • DFile encryption along with password protection

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    74% (28)
  • C
    8% (3)
  • D
    13% (5)

Explanation

The root cause of this incident was social engineering - an attacker manipulated a person into revealing a password. The most effective countermeasure is security awareness training, which equips employees to recognize and resist social engineering tactics. Technical controls like MFA (A) reduce the risk of credential compromise but do not address the human vulnerability exploited here - and social engineering can also be used to bypass MFA. Access log review (C) is a detective control, not preventive. File encryption with password protection (D) still relies on a secret that can be socially engineered.

Topics

#Social Engineering#Security Awareness#Employee Training#Preventative Controls

Community Discussion

No community discussion yet for this question.

Full CISA Practice