B, C and D all address the issue with staff not reporting breaches. D is relevant because it is possible breaches are not being reported because breaches arising from cyber attacks are not even being recognised. Whereas A considers why breaches are happening in the first place, which is a separate issue.
D. Distribute a phishing exercise to all employees to test their ability to recognize a threat attempt.
While testing employees with a phishing exercise is a good practice for increasing awareness about potential threats and improving security practices, it doesn't directly address the issue of colleagues not reporting known breaches.
I suggest D, the rest help in identifying or correcting the problem, doing a phishing test has no relation
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Rocketly
4 months, 3 weeks agoSsourav
1 year, 2 months agoemily0922
1 year, 3 months ago