ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 447 - CAS-004 discussion

Report
Export

An organization performed a risk assessment and discovered that less than 50% of its employees have been completing security awareness training. Which of the following should the Chief Information Security Officer highlight as an area of Increased vulnerability in a report to the management team?

A.
Social engineering
Answers
A.
Social engineering
B.
Third-party compromise
Answers
B.
Third-party compromise
C.
APT targeting
Answers
C.
APT targeting
D.
Pivoting
Answers
D.
Pivoting
Suggested answer: A

Explanation:

The Chief Information Security Officer (CISO) should highlight social engineering as an area of increased vulnerability due to the lack of completion of security awareness training by employees. Social engineering attacks exploit human behavior, and employees who are not adequately trained are more likely to fall victim to phishing, pretexting, and other types of social engineering tactics. Increasing awareness and training helps employees recognize and respond appropriately to these threats.

CompTIA CASP+ CAS-004 Exam Objectives: Section 4.3: Understand how to conduct risk management activities.

CompTIA CASP+ Study Guide, Chapter 9: Risk Management and Incident Response.


asked 02/10/2024
Michel Flipse
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first