Place the following steps of a phishing reporting and human risk management workflow in the correct chronological order, from initial end-user detection to awareness program refinement.
- 1An employee detects suspicious indicators in an incoming email, such as urgent financial demands from an unverified domain, and clicks the built-in phishing reporting plugin.
- 2An automated email triage platform isolates the reported message and forwards extracted metadata to security operations for verification.
- 3Security analysts confirm the message as an authentic spear-phishing attempt and push updated indicator-of-compromise (IoC) rules to the secure email gateway.
- 4The human risk management system records the successful user detection metric to update departmental vigilance telemetry.
- 5Targeted microlearning modules addressing social engineering techniques are automatically assigned to personnel in high-risk job roles exposed to the attack vector.
Answer
The correct workflow begins with user detection and reporting, followed by automated quarantine triage, technical analyst verification and gateway filter updating, recording user reporting telemetry, and deploying targeted role-based microlearning.
The correct sequence reflects the operational lifecycle of human threat reporting: initial user reporting, automated quarantine triage, SOC verification and technical containment, human risk telemetry logging, and adaptive role-based microlearning deployment.
Step-by-Step Solution
Key Concept
Phishing Incident Reporting and Human Risk Telemetry Workflow