312-50 Question 225
Select 2▪ Social Engineering CountermeasuresA company experiences a successful vishing attack in which an attacker impersonates an internal help desk technician and convinces several employees to reveal MFA push approval details and temporary verification codes. As part of the remediation plan, the security team wants to implement countermeasures that directly reduce the likelihood of the same social engineering technique succeeding again. Which TWO actions are the most effective?
- A
Require employees to independently verify help desk requests through a trusted internal directory or ticketing system before sharing account-related information or approving MFA prompts
- B
Increase password complexity requirements from 12 to 20 characters for all employees
- C
Provide recurring, role-based security awareness training that includes vishing simulations, callback procedures, and guidance that support staff will not ask for MFA codes or prompt approvals
- D
Block all inbound calls from unknown external phone numbers at the PBX level
- E
Enable screen locking after 5 minutes of inactivity on employee workstations
Show answer and explanation
Correct answers: A, C
Explanation
The best answers are the controls that directly mitigate the social engineering method used: impersonation over the phone to obtain sensitive authentication-related actions. In CEH-style scenarios, the strongest countermeasures are procedural verification and user awareness tailored to the attack channel. Requiring employees to verify support requests through trusted internal processes reduces reliance on caller identity claims. Role-based training with realistic vishing simulations helps users recognize pretexts, resist urgency, and follow approved verification steps. These controls align with widely accepted best practices from security awareness guidance and identity security recommendations, including the principle that help desk staff should never ask users to disclose one-time passcodes or approve unexpected MFA requests. The other options are legitimate security controls in other contexts, but they do not directly address the social engineering weakness exploited in this incident.
- A. Correct.
Correct. Independent verification is a core social engineering countermeasure. If employees confirm the caller's identity using a trusted source such as the corporate directory, internal ticket, or official help desk number, the attacker loses the advantage of pretexting. This directly addresses vishing by shifting trust from the inbound caller to an approved verification process.
- B. Incorrect.
Incorrect. Stronger passwords can improve resistance to password guessing or credential stuffing, but they do not directly prevent employees from being manipulated into disclosing MFA-related information during a phone-based social engineering attack. This option addresses a different attack vector than the one described.
- C. Correct.
Correct. Targeted security awareness training is one of the most effective defenses against social engineering. In this scenario, training should specifically cover vishing indicators, procedures for callback verification, and the rule that legitimate support personnel should not request MFA codes or ask users to approve unsolicited prompts. Simulations reinforce behavior under realistic conditions.
- D. Incorrect.
Incorrect. Blocking all unknown external calls is generally impractical for most organizations because it can disrupt legitimate business communications, vendors, and customers. It also does not address attacks that use spoofed internal numbers, compromised vendor numbers, or other channels such as SMS and collaboration tools. This is an overbroad control rather than a focused social engineering countermeasure.
- E. Incorrect.
Incorrect. Automatic screen locking is a valid security control for preventing unauthorized local access to unattended systems, but it does not meaningfully reduce the success of a vishing attack where employees are tricked into disclosing MFA information. It is good hygiene, but not the best answer for this scenario.