Following an incident where an attacker successfully impersonated an IT helpdesk technician over the phone to reset employee passwords, a security team is enhancing its human risk management program. The team seeks to implement targeted administrative controls and specialized training to prevent similar credential compromise incidents. Which of the following strategies represent appropriate human risk mitigation controls for this scenario? (Select TWO.)
- Establish mandatory out-of-band verification protocols when employees receive unprompted requests for credential updates or identity confirmation.Cevap
- Deliver role-based security awareness training focused on identifying voice phishing (vishing) tactics and phone-based social engineering.Cevap
- CDeploy host-based endpoint detection and response (EDR) agents to automatically analyze and terminate suspicious incoming phone calls.
- DReclassify all security awareness training materials as technical preventive controls within governance audit documentation.
Cevap
The correct controls are establishing mandatory out-of-band verification protocols for unprompted identity requests and delivering role-based security awareness training focused on voice phishing tactics.
Establishing out-of-band verification requires employees to authenticate phone requests using a secondary, independently verified communication channel (such as calling back an official internal extension). Combining this policy with role-based vishing awareness ensures personnel can recognize impersonation attempts and adhere to identity validation procedures.
Adım Adım Çözüm
Anahtar Kavram
Security Awareness and Human Risk Management Controls