712-50 Question 267
Single answerUnderstanding and protecting against Social Engineering in the age of Social MediaA global manufacturing company is preparing to announce a merger. The CISO learns that several senior executives frequently post travel schedules, conference appearances, and internal team celebrations on public social media accounts. During the last quarter, the company also experienced multiple highly targeted phishing emails that referenced real supplier names and executive assistants. The CEO asks for one security initiative that will most effectively reduce the organization's exposure to social engineering in the short term without disrupting the merger announcement timeline. Which action should the CISO prioritize?
- A
Implement a targeted executive social media risk management program that includes public-profile reviews, guidance on limiting sensitive business context in posts, and just-in-time spear-phishing awareness for high-risk staff
- B
Require all employees to make their personal social media accounts private and prohibit any mention of the company online
- C
Purchase a new email security gateway and defer user-focused controls until after the merger announcement is complete
- D
Instruct the communications team to stop all corporate social media activity until the merger is publicly announced
Show answer and explanation
Correct answer: A
Explanation
The best answer is Option 1 because it directly addresses the intersection of social media exposure and social engineering risk in a realistic, time-sensitive way. In merger periods, attackers often increase spear-phishing, impersonation, and business email compromise attempts by combining public information with organizational context. A CCISO should prioritize controls that are risk-based, targeted to the highest-value individuals, and feasible to deploy quickly.
Relevant best practices support this approach. NIST SP 800-61 emphasizes preparation and reducing attack opportunities before incidents occur. NIST SP 800-50 and broader security awareness guidance support role-based training rather than generic awareness alone. CIS Controls also emphasize security awareness training, account protection, and governance over publicly exposed information. From a leadership perspective, the action should balance risk reduction, business continuity, and practicality.
The key misconception in the other options is overreliance on either restrictive policy or technical controls alone. Effective protection against social engineering in the age of social media requires layered defense: reduce unnecessary public business context, improve awareness for high-risk personnel, and maintain technical detection and response capabilities.
- A. Correct.
Correct. This option addresses the actual attack path shown in the scenario: adversaries are using publicly available contextual information from social media to craft convincing social engineering attacks. A targeted executive social media risk management program is practical, risk-based, and aligned with short-term reduction of exposure. It combines governance and awareness by reviewing public-facing information, reducing oversharing of operational details, and focusing training on executives, executive assistants, and other high-value targets who are commonly impersonated or targeted in business email compromise and spear-phishing campaigns.
- B. Incorrect.
Incorrect. Although reducing public exposure may help, requiring all employees to privatize personal accounts and banning any company mention is generally impractical, difficult to enforce, and may create legal, HR, and cultural issues depending on jurisdiction and employment policy. It also does not directly address the need for targeted awareness and does not represent a balanced, risk-based control at the executive level.
- C. Incorrect.
Incorrect. Email security technology is important, but this option ignores the social engineering root cause highlighted in the scenario: attackers are enriching pretexting and phishing with information harvested from social media. Deferring user-focused controls leaves executives and assistants exposed during a high-risk period. A CCISO should prioritize layered controls rather than relying solely on technical filtering.
- D. Incorrect.
Incorrect. Pausing corporate social media activity may reduce some official disclosures, but it does not address the primary issue that executives are posting sensitive contextual information on personal or professional public accounts. It is also overbroad and may unnecessarily disrupt business operations without materially reducing the most relevant risk.