CRISC · Question #450
An insurance company handling sensitive and personal information from its customers receives a large volume of telephone requests and electronic communications daily. Which of the following is MOST im
The correct answer is C. Identifying social engineering attacks. For a customer service department handling sensitive customer information, training on identifying social engineering attacks is most important, as they are frequently targeted with such methods.
Question
An insurance company handling sensitive and personal information from its customers receives a large volume of telephone requests and electronic communications daily. Which of the following is MOST important to include in a risk awareness training session for the customer service department?
Options
- AArchiving sensitive information
- BUnderstanding the incident management process
- CIdentifying social engineering attacks
- DUnderstanding the importance of using a secure password
How the community answered
(49 responses)- A6% (3)
- B4% (2)
- C80% (39)
- D10% (5)
Why each option
For a customer service department handling sensitive customer information, training on identifying social engineering attacks is most important, as they are frequently targeted with such methods.
Archiving sensitive information is an important data retention policy, but typically handled by systems or specific procedures, not a primary daily risk for customer service reps in interaction.
Understanding the incident management process is important for all employees, but identifying how incidents (especially those starting with social engineering) occur is more critical for frontline staff than the detailed response process itself.
Customer service representatives often serve as a prime target for social engineering attacks due to their direct interaction with customers and access to sensitive information. Training them to identify tactics like phishing, vishing, and pretexting is crucial to prevent attackers from manipulating them into revealing confidential data or granting unauthorized access, thereby directly protecting customer PII and the organization's reputation.
While secure passwords are vital, social engineering attacks often bypass the need for a password by tricking an employee into revealing information or performing an action, making identification of the attack itself more immediate and crucial.
Concept tested: Social engineering attack awareness
Source: https://learn.microsoft.com/en-us/security/phishing/social-engineering-phishing
Topics
Community Discussion
No community discussion yet for this question.