Question

Difficulty: HardSecurity Awareness Programs and Human Risk Management

A healthcare enterprise discovers through internal audits that clinical staff frequently leave unattended workstations logged in during emergency patient interventions, creating a physical security and data privacy compliance risk. Standard annual security training has failed to reduce these occurrences. The security team needs to improve human risk management specifically for clinical personnel without impacting emergency response times. Which of the following controls represents the most effective administrative and operational security awareness strategy to mitigate this risk?

  1. Deploy context-aware role-based microlearning triggered after policy non-compliance events alongside automated proximity-based session locking.Answer
  2. B
    Increase the duration of annual general security awareness training from one hour to four hours and enforce mandatory retakes for failing employees.
  3. C
    Implement monthly unannounced simulated spear-phishing campaigns aimed specifically at clinical personnel during patient care shifts.
  4. D
    Reclassify workstation physical access control as a deterrent-only policy enforced exclusively via physical security guard patrols.

Answer

Deploy context-aware role-based microlearning triggered after policy non-compliance events alongside automated proximity-based session locking.
The correct answer effectively mitigates human risk by pairing automated proximity-based session locking with contextual, role-based microlearning. Microlearning targets specific operational behaviors immediately after non-compliant incidents occur, reinforcement learning without imposing lengthy, irrelevant course requirements on healthcare providers.

Step-by-Step Solution

1
Analyze the organizational scenario and identify the specific security risk.
Clinical staff are leaving active sessions unattended due to urgent patient care needs, representing a failure of generic security awareness training to change specific operational habits.
Effective human risk management requires understanding operational context and specific job role pressures.
2
Evaluate the effectiveness of generic training vs. targeted role-based training.
Generic annual security awareness programs are largely ineffective for targeted workflow issues. Contextual, role-based microlearning delivers targeted education immediately following policy violations or high-risk behaviors.
Targeted microlearning reinforces security behavior in digestible, relevant increments without interfering with job duties.
3
Select the best combined control strategy per Security+ standards.
Pairing technical proximity-based locking controls with contextual role-based microlearning provides automated risk reduction while reinforcing human behavior compliance.
CompTIA Security+ emphasizes aligning security awareness controls directly with specific threat vectors and operational roles.

Key Concept

Role-Based Security Awareness and Contextual Human Risk Management
Estimated Time:2m 0s
Rate this question