Question

Difficulty: EasySecurity Awareness Programs and Human Risk Management

An organization relies on end-user reporting to reduce human risk and mitigate phishing attacks. Place the following steps in the correct sequential order from initial end-user reporting to security awareness program escalation.

  1. 1An employee identifies suspicious red flags in an email and reports it using the email client's reporting button.
  2. 2Automated security systems analyze the reported email payload and verify the presence of a malicious link.
  3. 3Security operations purges identical phishing messages from all enterprise inboxes to contain exposure.
  4. 4The security awareness team integrates the new phishing tactic into upcoming employee training modules.

Answer

The correct order begins with employee reporting, followed by automated threat verification, enterprise inbox purging, and updating security awareness training.
The correct sequence follows logical security lifecycle operations: end-user detection and reporting, technical analysis and verification, enterprise-wide technical containment, and continuous feedback into the security awareness training program.

Step-by-Step Solution

1
Identify the initial reporting action.
The employee recognizes suspicious email indicators and reports the email.
Reporting procedures start with end-user recognition and submission.
2
Determine the technical analysis stage.
Automated tools analyze and verify the reported payload.
Technical analysis must immediately validate the report before broader incident containment actions occur.
3
Identify the technical containment response.
Security operations purges matching messages from all user inboxes.
Containment prevents other employees from interacting with the active threat.
4
Identify the program improvement feedback loop.
The security awareness team updates ongoing training based on the real-world attack vector.
Continuous feedback closes the loop by improving future human risk resilience against real-world tactics.

Key Concept

Incident Reporting and Security Awareness Feedback Loop
Rate this question