nerdexam
(ISC)2

CSSLP · Question #175

Which of the following methods can be helpful to eliminate social engineering threat? Each correct answer represents a complete solution. Choose three.

The correct answer is A. Password policies B. Data classification D. Vulnerability assessments. Effective methods to mitigate social engineering threats include implementing strong password policies, establishing data classification schemes, and regularly conducting vulnerability assessments.

Secure Software Deployment, Operations, Maintenance

Question

Which of the following methods can be helpful to eliminate social engineering threat? Each correct answer represents a complete solution. Choose three.

Options

  • APassword policies
  • BData classification
  • CData encryption
  • DVulnerability assessments

How the community answered

(35 responses)
  • A
    94% (33)
  • C
    6% (2)

Why each option

Effective methods to mitigate social engineering threats include implementing strong password policies, establishing data classification schemes, and regularly conducting vulnerability assessments.

APassword policiesCorrect

Strong password policies, requiring complex passwords and multi-factor authentication, reduce the impact of social engineering attempts that aim to trick users into revealing credentials, as stolen simple passwords become less useful.

BData classificationCorrect

Data classification helps users understand the sensitivity of information, making them more cautious when handling it and less likely to inadvertently disclose sensitive data through social engineering tactics.

CData encryption

Data encryption protects data at rest or in transit from unauthorized access if stolen, but it does not directly prevent a social engineering attack from occurring or tricking a user into disclosing information.

DVulnerability assessmentsCorrect

Vulnerability assessments identify weaknesses in systems and processes, including potential human vulnerabilities or lack of proper controls that social engineers might exploit, allowing for remediation before an attack.

Concept tested: Social engineering mitigation techniques

Source: https://learn.microsoft.com/en-us/compliance/regulatory/auditing-password-policy-settings

Topics

#Social Engineering#Security Controls#Security Awareness#Vulnerability Management

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice