nerdexam
Isaca

CRISC · Question #276

Which of the following is the BEST recommendation to address recent IT risk trends that indicate social engineering attempts are increasing in the organization?

The correct answer is A. Conduct a simulated phishing attack. To address increasing social engineering attempts, conducting a simulated phishing attack is the best recommendation as it directly tests and improves employee resilience.

Submitted by andres_qro· Apr 18, 2026Risk Response and Reporting

Question

Which of the following is the BEST recommendation to address recent IT risk trends that indicate social engineering attempts are increasing in the organization?

Options

  • AConduct a simulated phishing attack.
  • BUpdate spam filters
  • CRevise the acceptable use policy
  • DStrengthen disciplinary procedures

How the community answered

(16 responses)
  • A
    75% (12)
  • B
    6% (1)
  • C
    13% (2)
  • D
    6% (1)

Why each option

To address increasing social engineering attempts, conducting a simulated phishing attack is the best recommendation as it directly tests and improves employee resilience.

AConduct a simulated phishing attack.Correct

Simulated phishing attacks directly test user susceptibility to social engineering techniques and provide immediate, practical training opportunities to improve employee awareness and response. This hands-on approach is highly effective in reducing human vulnerability, which is the primary target of social engineering attacks.

BUpdate spam filters

Updating spam filters is a technical control that might help reduce email-based social engineering but does not address other forms (e.g., vishing, smishing) or the crucial human element of awareness.

CRevise the acceptable use policy

Revising the acceptable use policy provides guidelines but does not actively train or test users' ability to identify and resist social engineering attempts in real-time.

DStrengthen disciplinary procedures

Strengthening disciplinary procedures might deter non-compliance but does not educate employees on how to recognize and avoid social engineering attacks in the first place, which is a proactive measure.

Concept tested: Social engineering mitigation, security awareness training

Source: https://www.cisa.gov/resources-tools/resources/cybersecurity-best-practices/security-awareness-training

Topics

#Social engineering#Phishing simulation#Security awareness training#Risk treatment

Community Discussion

No community discussion yet for this question.

Full CRISC Practice