Soru

Zorluk: ZorSecurity Awareness Programs and Human Risk Management

An enterprise security organization discovers that executive assistants are repeatedly targeted by sophisticated spear-phishing campaigns requesting emergency wire transfers on behalf of senior leaders. Although the organization maintains a 98% completion rate on its general annual security awareness training, several personnel still authorized fraudulent transactions. Which of the following strategies represents the most effective human risk management control to mitigate this specific risk?

  1. Establish specialized, role-based training on executive impersonation techniques while instituting mandatory out-of-band verification policies for high-value financial requests.Cevap
  2. B
    Increase the frequency of standard enterprise-wide phishing simulations to weekly and enforce strict disciplinary penalties for employees who fail consecutive tests.
  3. C
    Reclassify executive assistants as high-risk internal threat actors and enforce strict administrative access restrictions prohibiting them from accessing external web portals.
  4. D
    Implement perimeter firewall filtering rules to detect and block incoming voice over IP (VoIP) smishing and vishing attacks targeting administrative mobile phones.

Cevap

The most effective human risk management strategy is establishing specialized, role-based training on executive impersonation techniques while instituting mandatory out-of-band verification policies for high-value financial requests.
Role-based training delivers tailored instruction aligned with specific job responsibilities and threat exposures (such as Business Email Compromise targeting finance or administrative personnel). Coupling role-based training with mandatory out-of-band verification ensures that requests for financial transactions are confirmed via an independent communication channel, effectively neutralizing human vulnerability to spoofed emails.

Adım Adım Çözüm

1
Analyze the threat scenario and organizational vulnerability.
Identified spear phishing and Business Email Compromise (BEC) specifically targeting executive assistants handling financial transactions.
General annual awareness training is insufficient for specialized high-risk roles subject to targeted social engineering.
2
Evaluate human risk mitigation controls.
Determine that role-based training equips personnel with context-specific threat recognition, while procedural controls (out-of-band verification) prevent single points of human failure.
Technical awareness combined with process safeguards lowers both the probability and impact of social engineering execution.

Anahtar Kavram

Role-Based Security Awareness and Out-of-Band Verification Controls
Tahmini Süre:2m 0s
Bu soruyu puanla