Question

Difficulty: MediumSecurity Awareness Programs and Human Risk Management

A healthcare organization is updating its human risk management framework to reduce vulnerabilities associated with visual eavesdropping and unauthorized physical media in patient treatment areas. Which of the following administrative and security awareness measures should the security team implement to specifically address these human risk vectors? (Select TWO.)

  1. Enforce clear screen guidelines requiring staff to lock unattended workstations and install privacy filters on terminals in public view.Answer
  2. B
    Deploy network access control policies to automatically block physical USB storage devices across all endpoint operating systems.
  3. Deliver role-based training modules instructing clinical personnel on recognizing and reporting suspicious physical USB drives found in facility areas.Answer
  4. D
    Mandate annual generic vishing simulations for clinical staff focused on phone-based financial wire transfer scams.

Answer

The organization should enforce clear screen guidelines with privacy filters and deliver role-based training focused on recognizing suspicious physical media.
Enforcing clear screen guidelines (mandating screen locks and privacy filters) directly counters physical shoulder surfing in high-traffic clinical areas. Providing role-based training on recognizing physical USB hazards equips personnel to counter baiting tactics effectively.

Step-by-Step Solution

1
Identify the specific human risk vectors described in the scenario.
The scenario highlights shoulder surfing (visual eavesdropping) and dropped physical removable media (baiting) in clinical environments.
Security awareness initiatives must directly align with the human behaviors and physical vectors observed in the work environment.
2
Evaluate administrative policies and awareness training responses.
Establishing clear screen standards (locking screens and using privacy filters) protects against visual observation. Role-based training regarding physical USB hazards teaches proper reporting of baiting attempts.
Both selected measures address the human element through policy enforcement and targeted education.
3
Differentiate technical enforcement and misaligned training modules.
Disabling ports via technical policy is a technical control, while generic wire-transfer vishing training targets an inappropriate threat vector for clinical staff.
CompTIA Security+ objectives require distinguishing administrative human risk controls from automated technical controls and ensuring training is role-relevant.

Key Concept

Role-based security awareness programs and administrative controls for human risk management
Rate this question