ExamGecko
Question list
Search
Search

Question 385 - CISM discussion

Report
Export

Which of the following is the BEST way to reduce the risk of security incidents from targeted email attacks?

A.
Implement a data loss prevention (DLP) system
Answers
A.
Implement a data loss prevention (DLP) system
B.
Disable all incoming cloud mail services
Answers
B.
Disable all incoming cloud mail services
C.
Conduct awareness training across the organization
Answers
C.
Conduct awareness training across the organization
D.
Require acknowledgment of the acceptable use policy
Answers
D.
Require acknowledgment of the acceptable use policy
Suggested answer: C

Explanation:

Conducting awareness training across the organization is the best way to reduce the risk of security incidents from targeted email attacks because it helps to educate and empower the employees to recognize and avoid falling for such attacks. Targeted email attacks, such as phishing, spear phishing, or business email compromise, rely on social engineering techniques to deceive and manipulate the recipients into clicking on malicious links, opening malicious attachments, or disclosing sensitive information. Awareness training can help to raise the level of security culture and behavior among the employees, as well as to provide them with practical tips and best practices to protect themselves and the organization from targeted email attacks. Therefore, conducting awareness training across the organization is the correct answer.

https://almanac.upenn.edu/articles/one-step-ahead-dont-get-caught-by-targeted-email-attacks

https://www.microsoft.com/en-us/security/business/security-101/what-is-business-email-compromise-bec

https://www.csoonline.com/article/3334617/what-is-spear-phishing-examples-tactics-and-techniques.html

asked 01/10/2024
Marcos Paulo da Natividade Ferreira
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first