CRISC · Question #588
A risk practitioner has been notified of a social engineering attack using artificial intelligence (AI) technology to impersonate senior management personnel. Which of the following would BEST…
The correct answer is D. Training and awareness of employees for increased vigilance. For social engineering attacks, especially those leveraging AI for impersonation, the most effective mitigation strategy is comprehensive employee training and awareness.
Question
A risk practitioner has been notified of a social engineering attack using artificial intelligence (AI) technology to impersonate senior management personnel. Which of the following would BEST mitigate the impact of such attacks?
Options
- ASubscription to data breach monitoring sites
- BSuspension and takedown of malicious domains or accounts
- CIncreased monitoring of executive accounts
- DTraining and awareness of employees for increased vigilance
How the community answered
(24 responses)- A4% (1)
- B8% (2)
- C13% (3)
- D75% (18)
Why each option
For social engineering attacks, especially those leveraging AI for impersonation, the most effective mitigation strategy is comprehensive employee training and awareness.
Subscription to data breach monitoring sites helps detect if data has been compromised, but it does not prevent or mitigate the impact of an active social engineering attack.
Suspension and takedown of malicious domains or accounts is a reactive measure that addresses the attack infrastructure after it has been identified, but it doesn't prevent the initial compromise or mitigate the impact on an already targeted employee.
Increased monitoring of executive accounts might help detect suspicious activity post-compromise but does not prevent the initial social engineering attempt or educate employees to avoid being victimized.
Social engineering attacks, particularly those using advanced AI impersonation, prey on human vulnerabilities rather than technical ones. Comprehensive training and awareness programs educate employees on recognizing the tactics, techniques, and red flags of such attacks, empowering them to question suspicious requests and follow proper verification protocols, thereby significantly mitigating the impact.
Concept tested: Social engineering defense
Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/insider-risk-management-user-training
Topics
Community Discussion
No community discussion yet for this question.