712-50 exam dumps

712-50 practice question 260 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 260

Single answer

A global financial services company has experienced several near-miss incidents involving employees being persuaded to share sensitive internal information over collaboration tools and personal mobile devices. In one case, a recently disgruntled employee was contacted by an attacker posing as an internal HR representative and was convinced to provide details about privileged administrators and upcoming system changes. The board has asked the CISO to implement a strategy that addresses emerging social engineering methods and reduces the risk of insider-assisted compromise without disrupting business operations. Which approach is the MOST effective?

  1. A

    Deploy a stronger email gateway and block external file-sharing links, since most social engineering attacks originate through phishing emails

  2. B

    Implement a risk-based insider threat program that combines role-tailored awareness training, verification procedures for sensitive requests across communication channels, behavioral monitoring with privacy and legal oversight, and clear reporting/escalation paths

  3. C

    Require all employees to sign stricter acceptable use policies and increase disciplinary penalties for policy violations related to information sharing

  4. D

    Prohibit employees from using personal mobile devices and social media for any work-related communication to eliminate social engineering exposure

Show answer and explanation

Correct answer: B

Explanation

The most effective executive-level response is a layered, risk-based insider threat and anti-social-engineering program rather than a single technical or policy control. Social engineering has evolved beyond traditional phishing into multi-channel attacks including vishing, smishing, collaboration-platform impersonation, QR-code lures, social media reconnaissance, and in some cases AI-enabled voice or content impersonation. These methods are especially dangerous when they target employees who are stressed, disgruntled, overworked, or have privileged access, increasing the likelihood of insider-assisted compromise.

Best practices reflected in this answer align with widely accepted security guidance such as NIST Cybersecurity Framework functions for awareness, detection, and response; NIST SP 800-50 on building information technology security awareness and training programs; NIST SP 800-61 on incident handling; and insider threat guidance from CERT/SEI and related governance practices. From a CCISO perspective, the key is to establish governance-backed controls that integrate people, process, and technology: targeted awareness based on job role and threat exposure; formal verification requirements for sensitive requests regardless of channel; monitoring and analytics for unusual behavior with appropriate legal, privacy, and HR oversight; and trusted reporting mechanisms so staff can escalate suspicious interactions quickly. This approach is more resilient, scalable, and aligned with business realities than relying only on email security, stricter penalties, or blanket bans.

  • A. Incorrect.

    This is insufficient because it focuses primarily on email-based controls, while the scenario specifically includes collaboration platforms, voice/text interactions, and personal mobile devices. Modern social engineering increasingly uses multi-channel approaches such as vishing, smishing, business messaging apps, deepfake-enabled impersonation, and pretexting. Email filtering is useful, but by itself it does not adequately address insider-assisted compromise or human verification failures across channels.

  • B. Correct.

    This is the best answer because it addresses both the human and process dimensions of social engineering and insider risk. A risk-based insider threat program aligns with executive-level governance responsibilities and recognizes that insider-assisted incidents often involve manipulation, coercion, pretexting, or exploitation of disgruntled staff. Role-based training is more effective than generic awareness, especially for high-risk groups such as administrators, HR, finance, and executives. Verification procedures such as out-of-band confirmation, callback validation, and need-to-know checks reduce susceptibility to impersonation across email, chat, phone, and mobile channels. Behavioral monitoring, when implemented with legal, HR, and privacy oversight, helps identify anomalous activity or heightened insider risk without becoming purely punitive. Clear reporting and escalation paths improve early detection and response.

  • C. Incorrect.

    This is a plausible governance measure but not the most effective response. Policies and consequences can support a security culture, but they do not by themselves counter sophisticated social engineering or address why employees comply with manipulated requests. Overreliance on punitive controls can also discourage reporting of suspicious interactions or mistakes, which weakens detection and response.

  • D. Incorrect.

    This option is overly restrictive and operationally impractical for many organizations. It also reflects a common misconception that banning technologies eliminates social engineering risk. Attackers can still use corporate channels, phone calls, in-person pretexting, or compromised accounts. Effective executive security strategy should reduce risk through layered controls, verification, awareness, and monitoring rather than relying solely on broad prohibitions that may impede business without addressing root causes.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam