SY0-301 · Question #440
After a number of highly publicized and embarrassing customer data leaks as a result of social engineering attacks by phone, the Chief Information Officer (CIO) has decided user training will reduce…
The correct answer is A. Information Security Awareness. Information Security Awareness training directly addresses the human vector exploited in social engineering attacks by teaching employees to recognize and resist manipulation tactics.
Question
After a number of highly publicized and embarrassing customer data leaks as a result of social engineering attacks by phone, the Chief Information Officer (CIO) has decided user training will reduce the risk of another data leak. Which of the following would be MOST effective in reducing data leaks in this situation?
Options
- AInformation Security Awareness
- BSocial Media and BYOD
- CData Handling and Disposal
- DAcceptable Use of IT Systems
How the community answered
(49 responses)- A88% (43)
- B4% (2)
- C2% (1)
- D6% (3)
Why each option
Information Security Awareness training directly addresses the human vector exploited in social engineering attacks by teaching employees to recognize and resist manipulation tactics.
Social engineering attacks exploit human psychology rather than technical vulnerabilities. Information Security Awareness training specifically teaches employees to recognize social engineering tactics (pretexting, vishing, impersonation), understand verification procedures before disclosing sensitive data, and follow proper protocols when receiving unsolicited phone requests - directly targeting and reducing the risk vector responsible for the data leaks.
Social Media and BYOD training addresses risks related to personal devices and social media usage, which is not directly relevant to phone-based social engineering attacks on customer data.
Data Handling and Disposal training covers proper management of physical and digital data assets, not the recognition and resistance of social engineering manipulation by phone.
Acceptable Use of IT Systems training defines proper use of company technology resources and does not address the human behavioral factors exploited in social engineering phone attacks.
Concept tested: Security awareness training to counter social engineering
Source: https://learn.microsoft.com/en-us/security/operations/incident-response-playbook-phishing
Topics
Community Discussion
No community discussion yet for this question.