Soru

Zorluk: KolaySecurity Awareness Programs and Human Risk Management

A chief information security officer (CISO) observes that system administrators are frequently targeted with sophisticated social engineering tactics tailored specifically to technical environments. Which training approach is most effective for addressing this human risk?

  1. Role-based security training designed around the elevated privileges and specific attack vectors of technical staffCevap
  2. B
    Universal annual baseline awareness training covering general corporate password policies for all employees
  3. C
    Immediate disciplinary escalation and credential revocation for any administrator who falls for a phishing simulation
  4. D
    Reclassifying social engineering defenses as network perimeter firewalls rather than administrative security awareness controls

Cevap

Role-based security training designed around the elevated privileges and specific attack vectors of technical staff
Role-based awareness training customizes educational material to match the responsibilities, privilege levels, and specific attack vectors encountered by distinct job roles such as system administrators.

Adım Adım Çözüm

1
Identify the target user group and their unique risk profile.
System administrators hold privileged access and face specialized social engineering threats.
Standard employee training does not cover high-privilege technical attack scenarios.
2
Select the appropriate security awareness program methodology.
Role-based training tailors content directly to specific job functions and threat vectors.
Tailored training effectively changes behavior for specialized operational roles.

Anahtar Kavram

Role-based security awareness and human risk management
Bu soruyu puanla