312-50 Question 223
Select 3▪ Social Engineering CountermeasuresA mid-sized company recently experienced a vishing attack in which an attacker, pretending to be a help desk technician, convinced several employees to reveal MFA push approvals and temporary VPN codes. The security team must implement countermeasures that reduce the success of similar social engineering attempts without significantly slowing legitimate support operations. Which THREE actions would be the most effective?
- A
Require employees to verify help desk requests using a separate, trusted channel such as the internal service portal or published support number before sharing credentials, approving MFA prompts, or disclosing one-time codes
- B
Replace all password-based authentication with longer password expiration intervals so employees are less likely to contact the help desk
- C
Implement regular role-based social engineering awareness training that includes vishing scenarios, MFA fatigue/prompt bombing, and procedures for reporting suspicious calls immediately
- D
Allow help desk staff to ask for one-time passcodes during urgent incidents, but only if the request is logged in the ticketing system
- E
Adopt help desk identity verification procedures such as caller validation, callback to registered numbers, and a policy that support staff must never request passwords, MFA approvals, or OTPs
Show answer and explanation
Correct answers: A, C, E
Explanation
The best answers are 1, 3, and 5 because effective social engineering countermeasures combine process controls, user education, and secure support procedures. In this scenario, the attacker succeeded by impersonating support personnel and exploiting trust, urgency, and confusion around MFA. The most appropriate response is therefore to harden verification workflows and train users to recognize and report these tactics.
Best practices from security awareness programs and identity security guidance consistently emphasize: verifying requests through trusted channels, enforcing clear policies that administrators and help desk staff never ask for passwords or one-time codes, and educating users about phishing, vishing, and MFA fatigue attacks. Guidance from organizations such as NIST supports phishing-resistant processes, least disclosure of authentication secrets, and security awareness training as administrative controls. Help desk procedures that rely on registered contact methods and callback validation are also standard operational safeguards.
Option 2 is not a meaningful countermeasure for this threat, and Option 4 is actively risky because it legitimizes unsafe requests for authentication factors. In real environments, once employees believe support may ask for OTPs or MFA approvals, attackers can easily imitate that behavior.
- A. Correct.
Correct. Out-of-band verification is a strong countermeasure against impersonation-based social engineering. If employees independently validate a request using a trusted source, such as the official service desk portal or a known internal number, the attacker loses the advantage of controlling the conversation. This is especially effective against vishing because voice familiarity or urgency can otherwise pressure users into bypassing normal checks.
- B. Incorrect.
Incorrect. Longer password expiration intervals do not address the root cause of this incident, which is social engineering and abuse of MFA/OTP workflows. In many environments, reducing unnecessary password resets can improve usability, but changing expiration timing is not a primary control for preventing employees from being tricked into approving MFA prompts or revealing temporary codes.
- C. Correct.
Correct. Targeted awareness training is one of the most practical social engineering countermeasures, especially when it goes beyond generic phishing examples. Training users on voice phishing, pretexting, MFA fatigue attacks, and immediate reporting procedures helps them recognize manipulation techniques and respond appropriately. Role-based training is particularly useful because help desk interactions, executives, and remote workers may face different attack patterns.
- D. Incorrect.
Incorrect. Logging a request in a ticketing system does not make the request safe. A fundamental best practice is that support staff should not ask users for passwords, one-time passcodes, or MFA approvals. Allowing exceptions during urgent incidents normalizes dangerous behavior and gives attackers a believable pretext to exploit. This option reflects a common misconception that documentation alone compensates for an insecure process.
- E. Correct.
Correct. Strong help desk verification procedures directly reduce the success rate of impersonation attempts. Callback procedures, validation against registered contact details, and a strict policy prohibiting requests for passwords, OTPs, or MFA approvals are core process controls. These measures preserve support operations while making it much harder for attackers to exploit trust in the help desk.