Question

Difficulty: MediumSecurity Awareness Programs and Human Risk Management

An organization is updating its incident response playbooks to better integrate end-user security awareness reporting with human risk management oversight. Place the following operational steps in the correct chronological sequence from initial detection by an employee to the continuous improvement of the security awareness program.

  1. 1An employee identifies an unfamiliar email containing a suspicious link and clicks the integrated phishing reporting button.
  2. 2Automated security tools analyze the email headers and execute the link in an isolated sandbox environment.
  3. 3The Security Operations Center (SOC) purges matching malicious emails from all enterprise mailboxes.
  4. 4Security awareness managers analyze reporting telemetry to update targeted role-based training scenarios.

Answer

The correct sequence begins with the employee reporting the suspicious message via the phishing button, followed by automated technical analysis of the email payload, enterprise-wide mailbox purging by the security operations team, and finally utilizing reporting metrics to update role-based security awareness scenarios.
The correct operational sequence moves from initial end-user detection and reporting, through automated analysis and SOC-driven enterprise containment, to utilizing telemetry to optimize the security awareness program.

Step-by-Step Solution

1
End-User Reporting
Suspicious email submitted to the incident triage queue
The incident reporting lifecycle begins when an employee recognizes a security anomaly and reports it.
2
Automated Technical Triage
Header analysis and payload detonation in a sandbox
Submitted artifacts must be analyzed automatically to verify malicious intent and extract indicators of compromise (IOCs).
3
Incident Containment
Global removal of identified malicious messages across all mailboxes
Confirmed threats must be remediated immediately across the enterprise mail environment to mitigate exposure.
4
Human Risk Telemetry & Program Adjustment
Refining security awareness simulations and role-based training based on real-world threat data
Telemetry from user reporting provides behavioral metrics to measure training efficacy and target ongoing risk management efforts.

Key Concept

Security Awareness Reporting Workflow and Human Risk Management
Rate this question