An enterprise is formalizing its end-to-end human risk management and incident feedback workflow following a social engineering attempt. Place the following procedural steps in the correct chronological order from initial end-user detection to long-term security awareness program optimization.
- 1An end user identifies suspicious indicators in an incoming message and triggers the automated phishing reporting add-in.
- 2Automated security orchestration tools analyze message headers and sandbox attached URLs, confirming a malicious spear-phishing payload.
- 3The incident response team executes mail tenant purge scripts to remove all instances of the malicious email from user inboxes across the enterprise.
- 4The security awareness team analyzes the specific attack tactics used and develops role-based micro-learning modules for targeted departments.
- 5Human risk managers update department risk scores and recalibrate baseline difficulty parameters for future simulated phishing campaigns.
Cevap
The correct chronological sequence is: 1) End-user detection and submission via reporting tool -> 2) Automated security triage and payload verification -> 3) Enterprise mailbox purging and technical containment -> 4) Development of targeted micro-learning based on attack tactics -> 5) Recalibration of human risk scores and future simulation parameters.
The correct sequence begins with user detection and reporting. Next, automated technical triage validates the malicious payload, followed by immediate enterprise containment (purging the emails). Once the active threat is contained, post-incident data is fed into the awareness program to create targeted micro-learning, and finally, organizational risk profiles and simulation parameters are recalibrated.
Adım Adım Çözüm
Anahtar Kavram
Incident-Driven Human Risk Management and Security Training Lifecycle