Question

Difficulty: MediumSecurity Awareness Programs and Human Risk Management

An organization's finance department frequently receives fraudulent email requests attempting to alter vendor wire transfer details. Although employees successfully complete mandatory annual security awareness training, several staff members recently processed unauthorized payment changes. Which of the following approaches represents the most effective security awareness and human risk management control to address this vulnerability?

  1. Deliver tailored, role-based microlearning and practical simulations enforcing out-of-band verification for payment change requests.Answer
  2. B
    Require all corporate staff across all departments to immediately re-watch the general baseline security awareness video.
  3. C
    Deploy network access control rules to isolate accounting workstations whenever external email attachments are opened.
  4. D
    Institute mandatory voice phishing (vishing) simulations focused exclusively on IT helpdesk password reset workflows.

Answer

Deliver tailored, role-based microlearning and practical simulations enforcing out-of-band verification for payment change requests.
Role-based training combined with targeted simulations provides specialized employees with relevant procedural defenses—such as verifying wire transfers using out-of-band communication—which effectively reduces human risk in high-exposure departments.

Step-by-Step Solution

1
Analyze the specific risk context and failure in existing controls.
General annual awareness training failed to prevent business email compromise (BEC) targeting financial payment workflows.
High-risk personnel require targeted instruction specific to their daily responsibilities rather than broad awareness concepts.
2
Evaluate candidate human risk controls against the target threat.
Role-based microlearning paired with practical out-of-band verification enforces specific behavioral defenses against BEC.
Verifying financial changes via an independent communication channel (out-of-band) directly mitigates email spoofing and social engineering.

Key Concept

Role-Based Security Awareness and Human Risk Mitigation
Rate this question