nerdexam
Isaca

CRISC · Question #222

An organization has been experiencing an increasing number of spear phishing attacks Which of the following would be the MOST effective way to mitigate the risk associated with these attacks?

The correct answer is C. implement a security awareness program. To mitigate the increasing number of spear phishing attacks, implementing a security awareness program is the most effective approach. This directly addresses the human element targeted by these sophisticated social engineering attempts.

Submitted by jaden.t· Apr 18, 2026Risk Response and Reporting

Question

An organization has been experiencing an increasing number of spear phishing attacks Which of the following would be the MOST effective way to mitigate the risk associated with these attacks?

Options

  • AUpdate firewall configuration
  • BRequire strong password complexity
  • Cimplement a security awareness program
  • DImplement two-factor authentication

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    17% (5)
  • C
    73% (22)
  • D
    3% (1)

Why each option

To mitigate the increasing number of spear phishing attacks, implementing a security awareness program is the most effective approach. This directly addresses the human element targeted by these sophisticated social engineering attempts.

AUpdate firewall configuration

Updating firewall configuration primarily protects against network-based attacks and does not prevent users from being tricked by emails that have already bypassed perimeter defenses.

BRequire strong password complexity

Requiring strong password complexity helps protect accounts once credentials are stolen but does not prevent the initial compromise where users might click malicious links or provide information through social engineering.

Cimplement a security awareness programCorrect

Spear phishing attacks specifically target individuals through personalized social engineering tactics. A robust security awareness program educates employees on how to identify suspicious emails, recognize social engineering cues, and properly report potential phishing attempts, making them the primary defense against these highly personalized threats.

DImplement two-factor authentication

Implementing two-factor authentication adds a layer of security to account access, but it doesn't prevent the initial compromise via a malicious link or file, nor does it prevent other forms of social engineering that don't immediately require password entry.

Concept tested: Mitigating social engineering and spear phishing

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-50.pdf

Topics

#Spear phishing#Security awareness#Risk mitigation#Social engineering

Community Discussion

No community discussion yet for this question.

Full CRISC Practice