ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 108 - CS0-003 discussion

Report
Export

A recent penetration test discovered that several employees were enticed to assist attackers by visiting specific websites and running downloaded files when prompted by phone calls. Which of the following would best address this issue?

A.
Increasing training and awareness for all staff
Answers
A.
Increasing training and awareness for all staff
B.
Ensuring that malicious websites cannot be visited
Answers
B.
Ensuring that malicious websites cannot be visited
C.
Blocking all scripts downloaded from the internet
Answers
C.
Blocking all scripts downloaded from the internet
D.
Disabling all staff members' ability to run downloaded applications
Answers
D.
Disabling all staff members' ability to run downloaded applications
Suggested answer: A

Explanation:

Increasing training and awareness for all staff is the best way to address the issue of employees being enticed to assist attackers by visiting specific websites and running downloaded files when prompted by phone calls. This issue is an example of social engineering, which is a technique that exploits human psychology and behavior to manipulate people into performing actions or divulging information that benefit the attackers. Social engineering can take many forms, such as phishing, vishing, baiting, quid pro quo, or impersonation. The best defense against social engineering is to educate and train the staff on how to recognize and avoid common social engineering tactics, such as:

Verifying the identity and legitimacy of the caller or sender before following their instructions or clicking on any links or attachments

Being wary of unsolicited or unexpected requests for information or action, especially if they involve urgency, pressure, or threats

Reporting any suspicious or anomalous activity to the security team or the appropriate authority

Following the organization's policies and procedures on security awareness and best practices

Official

Reference:

https://partners.comptia.org/docs/default-source/resources/comptia-cysa-cs0-002-exam-objectives

https://www.comptia.org/certifications/cybersecurity-analyst

https://www.comptia.org/blog/the-new-comptia-cybersecurity-analyst-your-questions-answered

asked 02/10/2024
Karine Bashala
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first