SY0-701 Question 478
Single answer5.6 Given a scenario, implement security awareness practices.A company recently had several employees disclose their usernames and MFA approval codes after receiving urgent phone calls from someone claiming to be from the internal IT help desk. The caller used the names of real managers found on social media and pressured employees to act quickly to avoid account lockouts. The security team wants to reduce the likelihood of this attack succeeding again through a security awareness initiative. Which action would BEST address the root cause?
- A
Train employees to independently verify help desk requests using approved internal contact methods and to never share passwords or MFA codes over phone, email, or chat
- B
Block all inbound phone calls from external numbers to prevent future vishing attempts
- C
Require employees to change their passwords every week so stolen credentials become invalid quickly
- D
Publish a company-wide list of IT administrators' direct mobile numbers so employees can identify legitimate callers
Show answer and explanation
Correct answer: A
Explanation
This scenario describes a vishing attack that uses impersonation, urgency, and information gathered from public sources to manipulate employees into revealing credentials and MFA approval information. Under security awareness best practices, the strongest response is targeted user training that reinforces verification procedures, recognition of social engineering indicators, and clear rules that passwords and MFA codes must never be shared. This aligns with common guidance from organizations such as NIST, including awareness and training principles in NIST SP 800-50 and identity and authentication practices in NIST SP 800-63. The root cause is not primarily a telephony issue or password age issue; it is failure to recognize and properly respond to social engineering attempts. Security awareness programs are most effective when they teach users how to verify requests through trusted internal channels and report suspicious interactions promptly.
- A. Correct.
Correct. This directly addresses the social engineering technique used in the scenario: vishing combined with impersonation and urgency. Effective security awareness training should teach users to verify requests through trusted channels, recognize pretexting and pressure tactics, and understand that legitimate support staff should not ask for passwords or MFA codes. This is a practical, scalable control that targets the human factor exploited in the incident.
- B. Incorrect.
Incorrect. Blocking all inbound external calls is not practical for most organizations and would disrupt legitimate business communications. It also does not address the underlying user behavior problem, since similar social engineering could occur through email, SMS, collaboration tools, or spoofed internal numbers.
- C. Incorrect.
Incorrect. Frequent password changes do not address the primary issue in this scenario, which is employees being tricked into disclosing credentials and MFA information. Modern guidance generally favors strong passwords, monitoring, and changes when compromise is suspected rather than unnecessarily frequent resets, which can lead to weaker user behavior.
- D. Incorrect.
Incorrect. Publishing direct mobile numbers may create additional exposure and does not solve the verification problem. Attackers can spoof phone numbers, and employees still need training to use approved verification procedures such as calling the help desk through the company directory or ticketing portal rather than trusting caller ID.