nerdexam
Isaca

CRISC · Question #588

A risk practitioner has been notified of a social engineering attack using artificial intelligence (AI) technology to impersonate senior management personnel. Which of the following would BEST…

The correct answer is D. Training and awareness of employees for increased vigilance. For social engineering attacks, especially those leveraging AI for impersonation, the most effective mitigation strategy is comprehensive employee training and awareness.

Submitted by haruto_sh· Apr 18, 2026Risk Response and Reporting

Question

A risk practitioner has been notified of a social engineering attack using artificial intelligence (AI) technology to impersonate senior management personnel. Which of the following would BEST mitigate the impact of such attacks?

Options

  • ASubscription to data breach monitoring sites
  • BSuspension and takedown of malicious domains or accounts
  • CIncreased monitoring of executive accounts
  • DTraining and awareness of employees for increased vigilance

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    13% (3)
  • D
    75% (18)

Why each option

For social engineering attacks, especially those leveraging AI for impersonation, the most effective mitigation strategy is comprehensive employee training and awareness.

ASubscription to data breach monitoring sites

Subscription to data breach monitoring sites helps detect if data has been compromised, but it does not prevent or mitigate the impact of an active social engineering attack.

BSuspension and takedown of malicious domains or accounts

Suspension and takedown of malicious domains or accounts is a reactive measure that addresses the attack infrastructure after it has been identified, but it doesn't prevent the initial compromise or mitigate the impact on an already targeted employee.

CIncreased monitoring of executive accounts

Increased monitoring of executive accounts might help detect suspicious activity post-compromise but does not prevent the initial social engineering attempt or educate employees to avoid being victimized.

DTraining and awareness of employees for increased vigilanceCorrect

Social engineering attacks, particularly those using advanced AI impersonation, prey on human vulnerabilities rather than technical ones. Comprehensive training and awareness programs educate employees on recognizing the tactics, techniques, and red flags of such attacks, empowering them to question suspicious requests and follow proper verification protocols, thereby significantly mitigating the impact.

Concept tested: Social engineering defense

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/insider-risk-management-user-training

Topics

#Social Engineering#Security Awareness Training#Risk Mitigation#AI Threats

Community Discussion

No community discussion yet for this question.

Full CRISC Practice