An organization is refining its human risk management and incident feedback lifecycle following a targeted social engineering campaign. Which of the following represents the correct chronological order of the operational and programmatic steps, from initial end-user discovery through security awareness curriculum escalation?
- 1An end-user detects suspicious phishing indicators in an incoming email and submits it using the automated reporting add-in.
- 2The Security Operations Center (SOC) triages the reported message, confirming an active credential harvesting attempt.
- 3The Incident Response team executes technical containment by invalidating active user sessions and blocking malicious domain indicators at the perimeter.
- 4Human Risk Management evaluates reporting metrics and latency across departments to identify highly targeted or vulnerable employee cohorts.
- 5The Security Awareness Program lead updates role-based training content and launches targeted phishing simulations mimicking the observed attack vector.
Answer
The correct chronological sequence is: 1) End-user detects and reports the suspicious email via reporting tool; 2) SOC triages the submission to confirm an active campaign; 3) Incident Response executes technical containment; 4) Human Risk Management evaluates metrics to identify vulnerable user cohorts; 5) Security Awareness lead updates training curriculum and launches targeted simulations.
The sequence reflects the standard operational and administrative lifecycle for human risk mitigation. The workflow starts when an end-user identifies and reports a suspicious message. Next, the SOC triages the report to confirm a malicious campaign. Once confirmed, the Incident Response team performs technical containment (e.g., revoking compromised sessions and blocklisting malicious domains). After technical risks are mitigated, Human Risk Management analyzes metrics such as reporting latency to identify vulnerable employee groups. Finally, Security Awareness updates training materials and deploys targeted simulations mirroring the attack vector to prevent future susceptibility.
Step-by-Step Solution
Key Concept
Integration of end-user incident reporting, human risk metrics, and iterative security awareness program updates.