An organization is establishing a security awareness program to reduce human risk from social engineering tactics. Which of the following initiatives represent core operational components of an effective security awareness and training program? (Select TWO).
- Delivering role-relevant micro-learning modules that highlight common phishing indicators during employee onboardingCevap
- BImplementing network firewall filtering to eliminate the need for end-user phishing identification
- Establishing simple, accessible mechanisms for employees to report suspected security incidents without fear of retributionCevap
- DTreating baseline awareness directives as optional guidelines rather than mandatory organizational policies
Cevap
Delivering role-relevant micro-learning modules during onboarding and establishing simple, non-punitive incident reporting mechanisms.
Delivering role-relevant micro-learning modules during onboarding equips personnel with essential skills to recognize phishing and social engineering. Additionally, implementing accessible, non-punitive reporting mechanisms encourages employees to alert security teams immediately when suspicious activity is detected.
Adım Adım Çözüm
Anahtar Kavram
Security Awareness Programs and Human Risk Management