nerdexam
CompTIA

SY0-301 · Question #440

After a number of highly publicized and embarrassing customer data leaks as a result of social engineering attacks by phone, the Chief Information Officer (CIO) has decided user training will reduce…

The correct answer is A. Information Security Awareness. Information Security Awareness training directly addresses the human vector exploited in social engineering attacks by teaching employees to recognize and resist manipulation tactics.

Security program management and oversight

Question

After a number of highly publicized and embarrassing customer data leaks as a result of social engineering attacks by phone, the Chief Information Officer (CIO) has decided user training will reduce the risk of another data leak. Which of the following would be MOST effective in reducing data leaks in this situation?

Options

  • AInformation Security Awareness
  • BSocial Media and BYOD
  • CData Handling and Disposal
  • DAcceptable Use of IT Systems

How the community answered

(49 responses)
  • A
    88% (43)
  • B
    4% (2)
  • C
    2% (1)
  • D
    6% (3)

Why each option

Information Security Awareness training directly addresses the human vector exploited in social engineering attacks by teaching employees to recognize and resist manipulation tactics.

AInformation Security AwarenessCorrect

Social engineering attacks exploit human psychology rather than technical vulnerabilities. Information Security Awareness training specifically teaches employees to recognize social engineering tactics (pretexting, vishing, impersonation), understand verification procedures before disclosing sensitive data, and follow proper protocols when receiving unsolicited phone requests - directly targeting and reducing the risk vector responsible for the data leaks.

BSocial Media and BYOD

Social Media and BYOD training addresses risks related to personal devices and social media usage, which is not directly relevant to phone-based social engineering attacks on customer data.

CData Handling and Disposal

Data Handling and Disposal training covers proper management of physical and digital data assets, not the recognition and resistance of social engineering manipulation by phone.

DAcceptable Use of IT Systems

Acceptable Use of IT Systems training defines proper use of company technology resources and does not address the human behavioral factors exploited in social engineering phone attacks.

Concept tested: Security awareness training to counter social engineering

Source: https://learn.microsoft.com/en-us/security/operations/incident-response-playbook-phishing

Topics

#security awareness training#social engineering#vishing#data leakage prevention

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice