nerdexam
Isaca

CISA · Question #294

Which of the following would be of GREATEST concern when testing an organization's controls around social engineering threats?

The correct answer is A. Incident handling procedures are not included in security awareness sessions. The greatest concern is the absence of incident handling procedures in security awareness sessions. Without proper training on how to recognize and respond to social engineering attempts, staff may fail to take appropriate actions when such threats occur. This can lead to greater

Submitted by yuki_2020· Apr 18, 2026Protection of Information Assets

Question

Which of the following would be of GREATEST concern when testing an organization’s controls around social engineering threats?

Options

  • AIncident handling procedures are not included in security awareness sessions
  • BStaff are not aware of information asset classifications
  • CBiometric authentication is not utilized
  • DThe intrusion detection system (IDS) is not configured properly

How the community answered

(38 responses)
  • A
    63% (24)
  • B
    18% (7)
  • C
    13% (5)
  • D
    5% (2)

Explanation

The greatest concern is the absence of incident handling procedures in security awareness sessions. Without proper training on how to recognize and respond to social engineering attempts, staff may fail to take appropriate actions when such threats occur. This can lead to greater vulnerability and an ineffective response to potential breaches, undermining the organization's overall security posture.

Topics

#Social Engineering#Security Awareness#Incident Response#Human Factors

Community Discussion

No community discussion yet for this question.

Full CISA Practice