Question

Difficulty: MediumSecurity Awareness Programs and Human Risk Management

An enterprise security team discovers that system administrators holding elevated credentials are being targeted by voice phishing (vishing) campaigns aimed at capturing out-of-band authentication codes. Despite 100% completion of the mandatory annual general security awareness course, several administrators compromised credentials during recent simulations. Which of the following approaches is the most effective human risk management intervention to mitigate this specific risk?

  1. Implement role-based micro-training and simulated vishing scenarios that enforce out-of-band identity verification protocols for privileged users.Answer
  2. B
    Increase the frequency of standard email spear-phishing simulation campaigns for all enterprise personnel from annually to quarterly.
  3. C
    Deploy network intrusion prevention system rules to automatically block call-signaling protocols on corporate firewall boundaries.
  4. D
    Reclassify the enterprise security awareness policy from an administrative guidance document to a detective security control in the risk register.

Answer

Implementing role-based micro-training and simulated vishing scenarios that enforce out-of-band identity verification protocols for privileged users is the most effective intervention.
Role-based training customizes security education to the specific threat landscape, access levels, and attack vectors associated with high-risk job functions. System administrators hold elevated permissions and are prime targets for vishing attacks attempting to harvest multi-factor authentication codes. Tailoring micro-training and practical vishing simulations with out-of-band verification procedures directly addresses the human risk associated with privileged roles.

Step-by-Step Solution

1
Analyze the threat vector and vulnerability context
The risk involves voice phishing (vishing) targeted specifically at privileged system administrators, an area where general annual awareness training proved ineffective.
Privileged roles face unique, high-impact attack vectors requiring specialized defense behaviors rather than general security rules.
2
Evaluate human risk management control types
Role-based training tailors content and practical simulations to high-risk roles and exact attack channels (vishing with out-of-band verification requirements).
Targeted simulations reinforce specific procedural responses (e.g., verifying callers out-of-band) necessary to reduce human risk.

Key Concept

Role-based security awareness training and human risk management tailoring for privileged accounts.
Rate this question