Soru

Zorluk: OrtaSecurity Awareness Programs and Human Risk Management

Following an incident where an attacker successfully impersonated an IT helpdesk technician over the phone to reset employee passwords, a security team is enhancing its human risk management program. The team seeks to implement targeted administrative controls and specialized training to prevent similar credential compromise incidents. Which of the following strategies represent appropriate human risk mitigation controls for this scenario? (Select TWO.)

  1. Establish mandatory out-of-band verification protocols when employees receive unprompted requests for credential updates or identity confirmation.Cevap
  2. Deliver role-based security awareness training focused on identifying voice phishing (vishing) tactics and phone-based social engineering.Cevap
  3. C
    Deploy host-based endpoint detection and response (EDR) agents to automatically analyze and terminate suspicious incoming phone calls.
  4. D
    Reclassify all security awareness training materials as technical preventive controls within governance audit documentation.

Cevap

The correct controls are establishing mandatory out-of-band verification protocols for unprompted identity requests and delivering role-based security awareness training focused on voice phishing tactics.
Establishing out-of-band verification requires employees to authenticate phone requests using a secondary, independently verified communication channel (such as calling back an official internal extension). Combining this policy with role-based vishing awareness ensures personnel can recognize impersonation attempts and adhere to identity validation procedures.

Adım Adım Çözüm

1
Analyze the incident scenario to identify the primary threat vector and human risk component.
The attack vector involves phone-based impersonation (vishing) targeting employees to reset passwords.
Understanding the attack mechanism is essential for selecting controls tailored to the specific human vulnerability.
2
Evaluate proposed administrative and awareness controls for mitigating phone-based social engineering.
Mandatory out-of-band verification prevents unauthorized password resets by confirming identity through an independent channel. Role-based training equips staff with knowledge of vishing tactics.
Combining procedural verification controls with targeted awareness training mitigates human susceptibility to social engineering.
3
Verify control classification and technical feasibility of distractor options.
Host EDR tools operate on computer endpoints and cannot manage telephone traffic. Training programs are administrative/operational controls, not technical controls.
Distinction between technical, operational, and administrative control categories ensures proper defense implementation.

Anahtar Kavram

Security Awareness and Human Risk Management Controls
Bu soruyu puanla