Soru

Zorluk: KolaySecurity Awareness Programs and Human Risk Management

An organization wants to reduce employee vulnerability to social engineering attacks where attackers impersonate internal IT support over the phone to collect passwords. Which of the following procedures should be emphasized during security awareness training to best mitigate this risk?

  1. Instruct employees to verify the caller's identity via an official internal directory using an out-of-band communication channel before disclosing sensitive information.Cevap
  2. B
    Configure workstation host firewalls to inspect incoming voice packets for spoofed telephone numbers.
  3. C
    Forward suspicious phone calls to the perimeter email security gateway for automated link scanning.
  4. D
    Treat identity verification requirements as optional guidance during high-priority IT outages.

Cevap

Instruct employees to verify the caller's identity via an official internal directory using an out-of-band communication channel before disclosing sensitive information.
Out-of-band verification requires employees to contact the requester using a trusted, independent method (such as dialing a verified internal extension from an enterprise directory) before sharing sensitive data. This procedure effectively neutralizes phone impersonation attacks.

Adım Adım Çözüm

1
Identify the threat vector described in the scenario.
The attack involves phone-based social engineering (vishing) targeting human trust.
Recognizing that human interaction is the vector helps select human-centric mitigation controls.
2
Evaluate the administrative and procedural awareness controls.
Establishing mandatory out-of-band verification via official internal contact channels prevents unauthorized credential disclosure.
Independent verification breaks the attacker's chain of trust and mitigates impersonation risks.

Anahtar Kavram

Out-of-band authentication and verification procedures in human risk management
Bu soruyu puanla