Question

Difficulty: Very hardSecurity Awareness Programs and Human Risk Management

An enterprise Chief Information Security Officer (CISO) observes that despite achieving a 100% completion rate on annual mandatory security awareness training, a targeted vishing and spear-phishing campaign against administrative staff resulted in multiple credential disclosures and zero incident reports to the Security Operations Center (SOC). Which of the following strategic enhancements to the security awareness and human risk management program should the organization implement to address these specific vulnerabilities? (Select TWO.)

  1. Transition from generic annual compliance modules to role-based, scenario-driven simulations tailored to specific job functions.Answer
  2. Integrate automated, continuous micro-learning sessions triggered directly by simulated phishing failures or high-risk user behaviors.Answer
  3. C
    Configure perimeter email security gateways to automatically block and quarantine all incoming messages containing external hyper-links.
  4. D
    Reclassify security awareness training as a technical detective control within the risk register to automate SIEM log parsing.

Answer

The organization should implement role-based, scenario-driven simulations tailored to specific job functions and integrate automated, continuous micro-learning sessions triggered by behavioral indicators or simulation failures.
Transitioning to role-based scenario-driven training and adopting continuous event-triggered micro-learning directly solve the weakness of passive compliance programs. They provide contextual education tailored to vulnerable job roles and reinforce security habits at the point of behavioral failure.

Step-by-Step Solution

1
Analyze the operational gap between awareness compliance and threat reporting capability.
High completion rates of generic annual training did not prevent credential harvesting or improve incident reporting rates during targeted social engineering attacks.
Generic compliance training satisfies regulatory mandates but fails to develop role-specific threat detection skills or reporting habits.
2
Identify effective administrative and behavioral human risk management controls.
Role-based simulations provide relevant contextual practice for targeted personnel, while event-driven micro-learning reinforces concepts immediately following high-risk actions.
Human risk reduction relies on continuous, contextual learning interventions that target high-vulnerability roles and behaviors.
3
Differentiate sound educational strategy from flawed administrative or technical controls.
Rejecting heavy-handed email blocking avoids breaking operational workflows, and maintaining awareness programs as administrative controls properly aligns governance frameworks.
Technical controls must balance business functionality with protection, and awareness training cannot substitute for automated technical monitoring controls.

Key Concept

Role-Based Security Training and Continuous Human Risk Mitigation
Rate this question