712-50 Question 262
Single answerAI powered Social Engineering, understand the context of IoT and Smart Devices, Deepfake technologyA global manufacturer is rolling out smart factory IoT devices and voice-enabled meeting room systems across multiple sites. During the same quarter, the company experiences two incidents: a plant manager receives a highly convincing AI-generated voice call that appears to come from the COO authorizing an urgent change to a third-party maintenance vendor's bank account, and several employees receive personalized messages referencing data apparently gathered from internet-exposed smart devices and corporate social media. The board asks the CISO for the MOST effective enterprise-level response that reduces immediate business risk while improving resilience against future AI-powered social engineering and deepfake attacks. Which action should the CISO prioritize FIRST?
- A
Deploy a companywide deepfake detection tool for voice and video, and require security staff to manually review flagged communications before any executive request is processed
- B
Implement out-of-band verification and transaction approval controls for sensitive requests, while accelerating governance for IoT exposure management, asset inventory, and least-privilege access to device data
- C
Ban the use of voice messages for executive communications and disconnect all smart devices from the corporate network until a full forensic review is completed
- D
Launch an awareness campaign focused on phishing indicators and require all employees to complete mandatory training on identifying synthetic media
Show answer and explanation
Correct answer: B
Explanation
The strongest CCISO response is to first reduce the organization's exposure to business-impacting fraud by implementing robust process controls for sensitive actions, especially those triggered by communications that could be spoofed using deepfake or AI-generated content. In practice, this means out-of-band verification, dual authorization, segregation of duties, callback to trusted numbers already on file, and change-management controls for vendor banking or financial transactions. These measures remain effective even when users cannot reliably distinguish real from synthetic media.
The scenario also highlights the role of IoT and smart devices in modern social engineering. Internet-exposed devices, poorly governed device data, and metadata from smart systems can provide attackers with environmental details, schedules, names, or operational context that make phishing, vishing, and impersonation significantly more credible. Therefore, the CISO should also drive IoT asset inventory, exposure reduction, network segmentation, secure configuration baselines, monitoring, and least-privilege access to device data.
This approach is consistent with widely accepted practices in NIST Cybersecurity Framework 2.0 and NIST SP 800-61/800-53 principles: focus on governance, asset management, protective controls, and resilient response processes rather than relying solely on user judgment or a single detection technology. It also reflects common anti-fraud controls used in financial governance and third-party risk management. For executive leadership, the key lesson is that deepfake risk is best managed through business-process assurance, not just media detection.
- A. Incorrect.
This is not the best first priority. Deepfake detection tools may help, but current detection capabilities can produce false positives and false negatives, especially as attackers adapt. Relying on manual review by security staff for every executive request also creates operational bottlenecks and does not address the underlying control failure: high-risk requests were actionable without independent verification. A CCISO-level response should prioritize durable business controls over point solutions.
- B. Correct.
This is the best answer because it addresses both the immediate fraud pathway and the broader intelligence-gathering problem that made the attacks more convincing. Out-of-band verification for payment changes, vendor banking updates, and other high-risk requests directly reduces business impact from AI-generated voice or video impersonation. Strengthening approval workflows, segregation of duties, and callback procedures to pre-registered contacts are proven anti-fraud measures. At the same time, improving IoT governance through asset inventory, exposure management, secure configuration, and least-privilege access reduces the data leakage and contextual information attackers can use for personalized social engineering. This response aligns with executive risk management responsibilities by combining preventive governance with detective and procedural controls.
- C. Incorrect.
This option is overly disruptive and not proportionate as a first response. Banning voice communications entirely is unlikely to be sustainable for the business, and disconnecting all smart devices without risk-based prioritization could interrupt operations, especially in a manufacturing environment. While emergency containment may be appropriate for specific compromised devices or systems, the scenario calls for an enterprise-level response that balances security with business continuity.
- D. Incorrect.
Training is valuable, but by itself it is insufficient as the first priority in a scenario involving executive impersonation, payment fraud risk, and exposure through smart devices. AI-powered social engineering often succeeds even against trained users because it exploits authority, urgency, and realistic contextual details. Awareness should support, not replace, formal verification controls and stronger governance over device exposure and sensitive workflows.