200-301 Question 413
Select 3A network administrator is implementing a security program for their organization. Which of the following actions align with best practices for user awareness, training, and physical access security?
- A
Conducting regular phishing simulation exercises to educate employees on identifying malicious emails.
- B
Allowing employees to use shared login credentials for ease of access to critical systems.
- C
Installing biometric authentication systems at critical data center access points.
- D
Providing new employees with a one-time cybersecurity training during onboarding, with no follow-up sessions.
- E
Creating a policy where employees must lock their workstations when stepping away from their desks.
Show answer and explanation
Correct answers: A, C, E
Explanation
A robust security program incorporates user awareness, regular training, and strong physical access controls. Conducting phishing simulations, utilizing biometric authentication, and enforcing workstation locking policies ensure employees are well-informed and sensitive areas are secure. Practices like using shared credentials or providing one-time training do not align with security best practices and can increase risk.
- A. Correct.
Conducting phishing simulation exercises helps build user awareness and trains employees to recognize and avoid phishing attacks, which is a key component of a security program.
- B. Incorrect.
Using shared login credentials is a poor security practice as it undermines accountability and increases the risk of unauthorized access. This does not align with security best practices.
- C. Correct.
Biometric authentication systems enhance physical security by ensuring only authorized individuals can access critical areas, making it an essential element of a security program.
- D. Incorrect.
Providing one-time training without follow-ups is inadequate. Security training should be an ongoing process to keep employees updated on evolving threats and best practices.
- E. Correct.
Requiring employees to lock their workstations when away is a fundamental security practice that prevents unauthorized access to sensitive data, aligning with user awareness and physical security principles.