nerdexam
Isaca

CISA · Question #336

Which of the following poses the GREATEST risk to an organization when employees use public social networking sites?

The correct answer is A. Social engineering. Public social networking profiles expose employee names, job titles, roles, team structures, technologies used, and professional relationships. Attackers harvest this information to craft highly credible phishing emails, pretexting calls, and spear-phishing campaigns - social eng

Submitted by fernanda_arg· Apr 18, 2026Protection of Information Assets

Question

Which of the following poses the GREATEST risk to an organization when employees use public social networking sites?

Options

  • ASocial engineering
  • BAdverse posts about the organization
  • CCross-site scripting (XSS)
  • DCopyright violations

How the community answered

(63 responses)
  • A
    49% (31)
  • B
    30% (19)
  • C
    13% (8)
  • D
    8% (5)

Explanation

Public social networking profiles expose employee names, job titles, roles, team structures, technologies used, and professional relationships. Attackers harvest this information to craft highly credible phishing emails, pretexting calls, and spear-phishing campaigns - social engineering attacks that can result in credential theft, unauthorized access, and data breaches. This risk is systemic and scales across every employee with a profile. Adverse posts (B) create reputational risk but not direct security compromise. XSS (C) is a web application vulnerability, not a primary social media risk for organizations. Copyright violations (D) are a compliance issue but not the greatest security threat.

Topics

#Social engineering#Information security threats#Risk management#Employee awareness

Community Discussion

No community discussion yet for this question.

Full CISA Practice