Soru

Zorluk: ZorSecurity Awareness Programs and Human Risk Management

Following a recent security audit, an enterprise identifies a surge in successful voice phishing (vishing) attacks targeting helpdesk staff to execute unauthorized multi-factor authentication (MFA) resets. Additionally, metrics indicate that end users rarely report suspicious phone calls due to a complex submission workflow and fear of disciplinary action for false alarms. Which of the following human risk management strategies should the organization implement to directly address these vulnerabilities? (Select TWO.)

  1. Establish role-based out-of-band identity verification protocols specifically for helpdesk personnel handling credential reset requests.Cevap
  2. Implement a non-punitive security reporting policy coupled with a simplified, single-click event reporting workflow.Cevap
  3. C
    Increase the duration and completion pass threshold of annual general security awareness computer-based training modules for all staff.
  4. D
    Reclassify helpdesk social engineering verification workflows as technical detective controls within the enterprise risk register.

Cevap

The organization should establish role-based out-of-band identity verification protocols for helpdesk personnel and implement a non-punitive security reporting policy with a simplified reporting workflow.
Establishing role-based out-of-band identity verification directly counters vishing attacks aimed at service desk personnel by enforcing strict operational authentication procedures. Additionally, implementing a non-punitive reporting policy with streamlined reporting channels addresses employee fear of false alarms, fostering a positive security culture that encourages immediate incident reporting.

Adım Adım Çözüm

1
Analyze the specific vulnerabilities identified in the scenario.
Identified two primary vulnerabilities: vishing attacks exploiting helpdesk MFA reset processes and user reporting friction caused by fear of reprimand and complex workflows.
Effective security awareness and human risk management require targeted controls aligned with root-cause indicators.
2
Evaluate role-based controls for helpdesk staff.
Out-of-band verification provides mandatory administrative guardrails that protect helpdesk agents from social engineering tactics.
Generic awareness training fails to protect specialized, high-risk roles that require strict operational verification standards.
3
Evaluate human risk management controls for user reporting behavior.
A non-punitive policy paired with simplified reporting channels directly lowers psychological and operational barriers to reporting threat indicators.
Encouraging a positive security reporting culture increases organizational detection capabilities and reduces mean time to detect (MTTD).

Anahtar Kavram

Role-Based Security Training and Human Risk Mitigation
Bu soruyu puanla