CRISC · Question #222
An organization has been experiencing an increasing number of spear phishing attacks Which of the following would be the MOST effective way to mitigate the risk associated with these attacks?
The correct answer is C. implement a security awareness program. To mitigate the increasing number of spear phishing attacks, implementing a security awareness program is the most effective approach. This directly addresses the human element targeted by these sophisticated social engineering attempts.
Question
An organization has been experiencing an increasing number of spear phishing attacks Which of the following would be the MOST effective way to mitigate the risk associated with these attacks?
Options
- AUpdate firewall configuration
- BRequire strong password complexity
- Cimplement a security awareness program
- DImplement two-factor authentication
How the community answered
(30 responses)- A7% (2)
- B17% (5)
- C73% (22)
- D3% (1)
Why each option
To mitigate the increasing number of spear phishing attacks, implementing a security awareness program is the most effective approach. This directly addresses the human element targeted by these sophisticated social engineering attempts.
Updating firewall configuration primarily protects against network-based attacks and does not prevent users from being tricked by emails that have already bypassed perimeter defenses.
Requiring strong password complexity helps protect accounts once credentials are stolen but does not prevent the initial compromise where users might click malicious links or provide information through social engineering.
Spear phishing attacks specifically target individuals through personalized social engineering tactics. A robust security awareness program educates employees on how to identify suspicious emails, recognize social engineering cues, and properly report potential phishing attempts, making them the primary defense against these highly personalized threats.
Implementing two-factor authentication adds a layer of security to account access, but it doesn't prevent the initial compromise via a malicious link or file, nor does it prevent other forms of social engineering that don't immediately require password entry.
Concept tested: Mitigating social engineering and spear phishing
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-50.pdf
Topics
Community Discussion
No community discussion yet for this question.