312-50 Question 220
Single answer▪ Identity TheftDuring an internal security assessment, a company asks you to evaluate how exposed its executives are to identity-theft-based social engineering. You discover that several executives publicly list their full birth dates, personal email addresses, hometowns, and employment history across social media and professional networking sites. The company wants the most effective immediate mitigation to reduce the risk that attackers will use this information to impersonate executives in account recovery and targeted phishing attacks. Which action should you recommend first?
- A
Implement an OS patch management program across executive laptops
- B
Reduce publicly exposed personally identifiable information (PII) and enforce privacy and awareness controls for executive online profiles
- C
Disable all executive VPN access until social media accounts are removed
- D
Require executives to change their passwords every 30 days without any other control changes
Show answer and explanation
Correct answer: B
Explanation
The best answer is to reduce publicly exposed PII and enforce privacy and awareness controls because the scenario specifically describes identity-theft-enabling information being openly available. In CEH-style assessments, candidates must identify the control that most directly addresses the attack path. Publicly available data such as date of birth, personal email, hometown, and employment history can be weaponized for impersonation, account recovery abuse, spear phishing, and profile-based fraud. Best practices from security awareness guidance, NIST identity and digital identity references, and general account security recommendations support minimizing exposed personal data, restricting privacy settings, and training users to avoid oversharing. While patching, VPN restrictions, and password changes all have value in broader security programs, they do not immediately mitigate the specific identity theft vector described in this scenario.
- A. Incorrect.
This is incorrect. Patch management is important for reducing vulnerability exploitation on endpoints, but it does not directly address the identified identity theft risk in the scenario. The immediate issue is excessive public exposure of PII that can be used for impersonation, password reset abuse, and highly tailored phishing.
- B. Correct.
This is correct. The scenario centers on attackers gathering publicly available personal data to facilitate identity theft and impersonation. Reducing exposed PII, tightening privacy settings, limiting publication of personal details, and training executives on oversharing directly mitigates the root cause. This is the most effective immediate step to reduce the attacker's ability to answer knowledge-based questions, craft believable phishing messages, or build fraudulent identities around the executives.
- C. Incorrect.
This is incorrect. Disabling VPN access is a disruptive control that does not address how attackers are collecting identity information. It may reduce some access risk temporarily, but it is not a proportionate or targeted first response to public PII exposure and social-engineering risk.
- D. Incorrect.
This is incorrect. Password changes may help if credentials are already suspected to be compromised, but identity theft attacks often rely on profile building, password-reset abuse, business email compromise pretexting, or social engineering rather than direct use of current passwords. Frequent password rotation alone is not considered a strong standalone mitigation and does not fix the exposed PII problem.