Soru

Zorluk: ZorSecurity Awareness Programs and Human Risk Management

A global logistics organization recently discovered that unauthorized personnel gained entry to restricted warehouse areas because employees were allowing unbadged individuals to follow them through access doors and sharing proximity smart cards during shift changes. Which TWO of the following human risk management and security awareness initiatives should the security analyst implement to directly remediate these specific non-technical security violations? (Select TWO.)

  1. Role-based physical security awareness training tailored to facility staff emphasizing single-person entry compliance and the hazards of badge sharingCevap
  2. B
    Automated anti-passback mechanisms integrated into electronic access control turnstiles at facility perimeter checkpoints
  3. A targeted security campaign reinforcing credential accountability supported by routine, unannounced physical access oversight auditsCevap
  4. D
    Quarterly simulated spear-phishing assessments targeting warehouse shift supervisors to evaluate click-through and threat reporting rates

Cevap

The correct responses are role-based physical security awareness training tailored to facility staff emphasizing single-person entry compliance and the hazards of badge sharing, as well as a targeted security campaign reinforcing credential accountability supported by routine, unannounced physical access oversight audits.
Role-based physical security awareness training directly addresses high-risk employee behaviors by educating staff on physical entry protocols and the dangers of card sharing. Additionally, combining credential accountability campaigns with unannounced physical access audits provides operational oversight and reinforces behavioral compliance across facility staff.

Adım Adım Çözüm

1
Analyze the reported security incident and identify the underlying risk vectors.
The incidents stem from human risk behaviors: tailgating (social engineering/complacency) and physical credential sharing.
Correct mitigation requires selecting human risk and awareness program controls tailored specifically to physical access violations.
2
Evaluate the administrative and operational awareness controls against the scenario requirements.
Role-based physical security training educates employees on tailgating, while credential accountability campaigns paired with access audits enforce operational compliance.
These controls directly target the human factors involved in physical security policy breaches.
3
Differentiate administrative/awareness controls from technical controls and mismatched threat vectors.
Anti-passback is a technical control rather than an awareness initiative, and phishing simulations target digital vector attacks rather than physical breaches.
CompTIA Security+ requires distinguishing administrative awareness solutions from technical physical security controls.

Anahtar Kavram

Role-based awareness training and operational human risk management strategies for physical security compliance.
Bu soruyu puanla