ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 358 - CS0-003 discussion

Report
Export

A Chief Information Security Officer (CISO) has determined through lessons learned and an associated after-action report that staff members who use legacy applications do not adequately understand how to differentiate between non-malicious emails and phishing emails. Which of the following should the CISO include in an action plan to remediate this issue?

A.

Awareness training and education

Answers
A.

Awareness training and education

B.

Replacement of legacy applications

Answers
B.

Replacement of legacy applications

C.

Organizational governance

Answers
C.

Organizational governance

D.

Multifactor authentication on all systems

Answers
D.

Multifactor authentication on all systems

Suggested answer: A

Explanation:

Awareness training and education are essential to help staff recognize phishing emails and understand safe email practices, particularly when using legacy applications that might not have the latest security features. Training helps build a culture of security mindfulness, which is critical for preventing social engineering attacks. According to CompTIA Security+ and CySA+ frameworks, user education is a fundamental aspect of organizational defense against phishing. Options like replacing applications or implementing MFA (while helpful) do not directly address the need for user awareness in this scenario.

asked 17/10/2024
Matthew Montgomery
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first