nerdexam
Isaca

CRISC · Question #450

An insurance company handling sensitive and personal information from its customers receives a large volume of telephone requests and electronic communications daily. Which of the following is MOST im

The correct answer is C. Identifying social engineering attacks. For a customer service department handling sensitive customer information, training on identifying social engineering attacks is most important, as they are frequently targeted with such methods.

Submitted by dimitri_ru· Apr 18, 2026Information Technology and Security

Question

An insurance company handling sensitive and personal information from its customers receives a large volume of telephone requests and electronic communications daily. Which of the following is MOST important to include in a risk awareness training session for the customer service department?

Options

  • AArchiving sensitive information
  • BUnderstanding the incident management process
  • CIdentifying social engineering attacks
  • DUnderstanding the importance of using a secure password

How the community answered

(49 responses)
  • A
    6% (3)
  • B
    4% (2)
  • C
    80% (39)
  • D
    10% (5)

Why each option

For a customer service department handling sensitive customer information, training on identifying social engineering attacks is most important, as they are frequently targeted with such methods.

AArchiving sensitive information

Archiving sensitive information is an important data retention policy, but typically handled by systems or specific procedures, not a primary daily risk for customer service reps in interaction.

BUnderstanding the incident management process

Understanding the incident management process is important for all employees, but identifying how incidents (especially those starting with social engineering) occur is more critical for frontline staff than the detailed response process itself.

CIdentifying social engineering attacksCorrect

Customer service representatives often serve as a prime target for social engineering attacks due to their direct interaction with customers and access to sensitive information. Training them to identify tactics like phishing, vishing, and pretexting is crucial to prevent attackers from manipulating them into revealing confidential data or granting unauthorized access, thereby directly protecting customer PII and the organization's reputation.

DUnderstanding the importance of using a secure password

While secure passwords are vital, social engineering attacks often bypass the need for a password by tricking an employee into revealing information or performing an action, making identification of the attack itself more immediate and crucial.

Concept tested: Social engineering attack awareness

Source: https://learn.microsoft.com/en-us/security/phishing/social-engineering-phishing

Topics

#Social Engineering#Risk Awareness Training#Customer Service Security#Information Security Threats

Community Discussion

No community discussion yet for this question.

Full CRISC Practice