712-50 Question 261
Single answerA global financial services company has seen a rise in highly personalized messages sent to employees through SMS, collaboration tools, and personal email accounts. In one incident, a departing project manager was persuaded by an external attacker posing as a recruiter to upload client transition documents to a personal cloud drive for a 'portfolio review.' The CISO's review shows that annual awareness training completion is high, but reporting of suspicious messages is low, and privileged users are often exempted from simulated phishing exercises to avoid operational disruption. Which action would MOST effectively reduce the risk of social engineering-enabled insider incidents while aligning with executive-level governance responsibilities?
- A
Mandate a more difficult annual CBT module for all staff and increase disciplinary action for anyone who clicks a phishing link
- B
Implement a risk-based anti-social-engineering program that includes role-based simulations across email, SMS, voice, and collaboration platforms; targeted controls for high-risk users and leavers; easy reporting; and metrics tied to insider-risk governance
- C
Block all personal email and public cloud storage access from corporate devices and rely on DLP alerts to identify future cases
- D
Outsource phishing detection entirely to the SOC and remove employee reporting requirements to reduce false positives
Show answer and explanation
Correct answer: B
Explanation
The best answer is the risk-based, governance-driven program because the scenario highlights a mature-looking but ineffective awareness model: high training completion, low reporting, privileged-user exemptions, and a social engineering pathway that contributed to insider-like behavior during employee departure. CCISO-level decision making should prioritize enterprise governance, risk treatment, and cross-functional controls rather than a single technical or disciplinary response.
Effective best practices include: role-based awareness and simulations; coverage of emerging channels such as SMS, voice, QR-based lures, collaboration platforms, and personal email pretexting; strong reporting mechanisms such as one-click reporting and hotline/chat escalation; focused controls for executives, privileged users, finance personnel, third parties, and leavers; and integration with insider-risk, HR, legal, and incident response processes. For departing staff, organizations commonly tighten monitoring, review access, reinforce acceptable-use obligations, and ensure secure offboarding.
This approach is consistent with broadly accepted guidance. NIST SP 800-50 emphasizes role-based awareness and ongoing security learning rather than one-time training. NIST's insider threat guidance and the NIST Cybersecurity Framework stress governance, detection, response, and cross-functional coordination. ISO/IEC 27001 and ISO/IEC 27002 support security awareness, access control, acceptable use, incident reporting, and personnel-related controls throughout the employment lifecycle. Together, these support a defense-in-depth strategy against social engineering and insider-enabled compromise.
- A. Incorrect.
This is incorrect because it overemphasizes annual computer-based training and punitive measures, which often reduce trust and discourage reporting. Modern social engineering defense requires continuous, behavior-focused reinforcement, realistic exercises, and a supportive reporting culture rather than relying mainly on punishment. Someone might choose this because increased training seems intuitive, but completion rates alone do not demonstrate resilience.
- B. Correct.
This is correct because it addresses the actual risk pattern: multichannel social engineering, insider-facilitated data movement, and governance gaps. A risk-based program should cover emerging vectors such as smishing, vishing, business communication compromise through collaboration tools, and pretexting via personal channels. It should also focus on higher-risk populations such as privileged users, executives, finance staff, contractors, and departing employees. Executive oversight should include measurable reporting, simulation outcomes, exception management, and integration with insider-risk and HR processes. This is the most comprehensive and governance-aligned response.
- C. Incorrect.
This is incorrect because it is too narrowly technology-centric and may be operationally impractical or incomplete. Blocking some channels can reduce exposure, but attackers frequently pivot to unmanaged devices or non-corporate channels. DLP is helpful as a detective and preventive control, but by itself it does not address human susceptibility, pretexting, coercion, or the need for a strong reporting culture and risk-based monitoring of leavers and privileged users.
- D. Incorrect.
This is incorrect because social engineering defense cannot be delegated solely to the SOC. Employees are critical sensors for attacks that bypass technical controls, especially in SMS, voice, and collaboration apps. Removing reporting requirements weakens detection and response. A candidate may choose this believing centralization improves efficiency, but it creates blind spots and undermines a key control: rapid user reporting.