ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 345 - CAS-004 discussion

Report
Export

A Chief Security Officer (CSO) is concerned about the number of successful ransomware attacks that have hit the company. The data Indicates most of the attacks came through a fake email. The company has added training, and the CSO now wants to evaluate whether the training has been successful. Which of the following should the CSO implement?

A.
Simulating a spam campaign
Answers
A.
Simulating a spam campaign
B.
Conducting a sanctioned vishing attack
Answers
B.
Conducting a sanctioned vishing attack
C.
Performing a risk assessment
Answers
C.
Performing a risk assessment
D.
Executing a penetration test
Answers
D.
Executing a penetration test
Suggested answer: A

Explanation:

A spam campaign is a mass distribution of unsolicited or fraudulent emails that may contain malicious links, attachments, or requests. Spam campaigns are often used by attackers to deliver ransomware, which is a type of malware that encrypts the victim’s data and demands a ransom for its decryption.

Simulating a spam campaign would allow the Chief Security Officer (CSO) to evaluate whether the training has been successful in reducing the number of successful ransomware attacks that have hit the company, because it would:

Test the employees’ ability to recognize and avoid clicking on fake or malicious emails, which is one of the main vectors for ransomware infection.

Measure the effectiveness of the training by comparing the click-through rate and the infection rate before and after the training.

Provide feedback and reinforcement to the employees by informing them of their performance and reminding them of the best practices for email security.

asked 02/10/2024
Zahid Maqsood
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first