200-301 Question 412
Select 3A company is implementing a security program to protect its sensitive information. Which combination of measures should be included to address user awareness, training, and physical access control?
- A
Conduct regular phishing simulation exercises for employees to recognize email threats.
- B
Require multi-factor authentication (MFA) for all remote access to internal systems.
- C
Install security cameras and implement badge access systems for entry points.
- D
Provide mandatory cybersecurity training sessions for all employees.
- E
Regularly update firewall policies to block unauthorized traffic.
Show answer and explanation
Correct answers: A, C, D
Explanation
An effective security program should include measures to educate users (phishing simulations, training sessions) and control physical access to sensitive areas (security cameras and badge systems). These elements help reduce human error and unauthorized physical access, both of which are critical for safeguarding an organization's resources.
- A. Correct.
Conducting phishing simulation exercises increases user awareness by helping employees recognize and respond to potential phishing attacks.
- B. Incorrect.
While multi-factor authentication is a critical security measure, it addresses authentication and access control rather than user awareness, training, or physical access.
- C. Correct.
Installing security cameras and badge access systems enhances physical access control, which is a critical element of a security program.
- D. Correct.
Mandatory cybersecurity training sessions ensure employees are educated on best practices and potential risks, directly addressing the training component of a security program.
- E. Incorrect.
Updating firewall policies is important for network security but does not specifically target user awareness, training, or physical access control.