712-50 Question 263
Single answerAI powered Social Engineering, understand the context of IoT and Smart Devices, Deepfake technologyA multinational manufacturer has recently connected smart cameras, badge readers, and voice-enabled conference devices across its offices and plants. During a quarterly close, the finance director receives what appears to be a live video call from the CIO instructing an urgent change to a supplier bank account due to a "regulatory hold." At the same time, a facilities manager reports that several IoT cameras briefly went offline and then reconnected from an external IP range associated with a third-party support provider. The SOC later determines the video call was an AI-generated deepfake, and logs suggest the attacker may have used exposed smart-device metadata and compromised vendor access to make the request highly convincing. As the CCISO, what is the MOST appropriate strategic response to reduce the risk of similar attacks while supporting business operations?
- A
Implement a cross-functional policy requiring out-of-band verification for high-risk requests, tighten third-party access to IoT management paths, and expand asset/data classification to include smart-device telemetry and media exposure
- B
Ban all voice and video communications for financial approvals and replace all smart devices with non-networked alternatives at every site
- C
Focus primarily on deploying a deepfake detection tool for executive video calls, since the main failure was the inability to identify synthetic media in real time
- D
Delegate the issue to facilities and procurement because IoT devices and vendor access are operational matters rather than enterprise information security risks
Show answer and explanation
Correct answer: A
Explanation
The best answer is the one that applies defense in depth and executive-level governance to an emerging threat. AI-powered social engineering and deepfake fraud are best mitigated by strengthening business process controls, especially for high-impact transactions such as payroll, supplier account changes, and wire transfers. Out-of-band verification using a trusted secondary channel is widely recommended in anti-fraud and business email compromise guidance because it remains effective even when the primary communication channel appears authentic. In parallel, smart devices and IoT systems should be treated as meaningful enterprise assets: inventories should be maintained, access should be segmented and least-privilege, vendor access should be tightly controlled, and logs should be monitored. From a governance perspective, classification should extend beyond traditional documents to include recordings, metadata, device telemetry, and environmental information that may improve attacker pretexting. This approach is consistent with broadly accepted practices from NIST guidance on IoT cybersecurity and cyber fraud risk reduction, as well as zero trust and third-party risk management principles. The key CCISO insight is that the strategic response must address organizational process, supplier risk, and smart-device exposure together rather than relying on a single technical product.
- A. Correct.
Correct. This is the most appropriate strategic response because it addresses the people, process, and technology dimensions of the incident. Out-of-band verification for sensitive actions such as payment changes is a strong control against AI-powered social engineering and business email compromise variants, regardless of whether the attack uses voice, video, or text. Tightening third-party access to IoT management paths addresses the likely intrusion vector and reduces the attacker's ability to collect device metadata, manipulate devices, or gain environmental context. Expanding asset and data classification to include smart-device telemetry, recordings, and metadata recognizes that IoT and collaboration devices can expose information useful for pretexting and deepfake-enabled fraud. This aligns with governance-focused security leadership responsibilities expected of a CCISO.
- B. Incorrect.
Incorrect. Although reducing risky channels can seem attractive after a deepfake incident, banning all voice and video communications and replacing all smart devices is disproportionate, operationally disruptive, and not risk-based. It does not reflect sound executive security governance or practical enterprise risk management. A CCISO should recommend layered controls that preserve business operations while reducing risk, not extreme measures without cost-benefit justification.
- C. Incorrect.
Incorrect. Deepfake detection technology may be useful as one layer of defense, but making it the primary response is too narrow. The incident was not only a media authenticity problem; it also involved process failure around approval validation, likely third-party access weakness, and exposure from smart-device data. Detection tools can produce false positives and false negatives, and current best practice is to combine technical controls with robust verification workflows and vendor risk management.
- D. Incorrect.
Incorrect. This reflects a governance failure. IoT devices, smart office systems, and vendor access are enterprise security concerns because they can affect confidentiality, integrity, availability, fraud exposure, and business resilience. A CCISO is expected to coordinate with facilities, procurement, legal, and IT, not treat these domains as outside the security program. The scenario explicitly shows how operational technology and smart devices can be leveraged in social engineering.