An organization wants to reduce employee vulnerability to social engineering attacks where attackers impersonate internal IT support over the phone to collect passwords. Which of the following procedures should be emphasized during security awareness training to best mitigate this risk?
- Instruct employees to verify the caller's identity via an official internal directory using an out-of-band communication channel before disclosing sensitive information.Answer
- BConfigure workstation host firewalls to inspect incoming voice packets for spoofed telephone numbers.
- CForward suspicious phone calls to the perimeter email security gateway for automated link scanning.
- DTreat identity verification requirements as optional guidance during high-priority IT outages.
Answer
Instruct employees to verify the caller's identity via an official internal directory using an out-of-band communication channel before disclosing sensitive information.
Out-of-band verification requires employees to contact the requester using a trusted, independent method (such as dialing a verified internal extension from an enterprise directory) before sharing sensitive data. This procedure effectively neutralizes phone impersonation attacks.
Step-by-Step Solution
Key Concept
Out-of-band authentication and verification procedures in human risk management