exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 422 discussion

Actual exam question from Isaca's CISM
Question #: 422
Topic #: 1
[All CISM Questions]

Which of the following is the BEST way to reduce the risk associated with a successful social engineering attack targeting help desk staff?

  • A. Conduct security awareness training
  • B. Implement two-factor authentication
  • C. Block access to social media sites
  • D. Enforce role based access to help desk systems
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
richck102
Highly Voted 1 year, 10 months ago
A. Conduct security awareness training
upvoted 6 times
...
HN2025
Most Recent 2 months, 3 weeks ago
Selected Answer: D
I believe that the answer is D. The question says associated with successful attack and If we consider that the attack has already happened, the focus should be on measures to mitigate the impact and prevent future occurrences. Comparing between B and D, D is the better answer, Enforce role-based access to help desk systems. Enforcing role-based access control (RBAC) directly aligns with the principles of limiting access based on the principle of least privilege. This means that even if an attacker successfully targets help desk staff, the potential damage is minimized because the compromised account would only have the minimum necessary access. This helps in containing the breach and reducing its impact. While B. Implement two-factor authentication enhances overall security and helps prevent unauthorized access, it is more about prevention rather than mitigating the impact after a successful attack.
upvoted 1 times
...
Josef4CISM
3 months, 2 weeks ago
Selected Answer: A
Social engineering can be prevented by increasing user awareness
upvoted 1 times
...
Raven89
5 months, 4 weeks ago
social eng is not only phishing ! Think to a phone call, tailgaiting etc .... it is always training A
upvoted 2 times
...
03allen
11 months, 2 weeks ago
Selected Answer: B
It says a successful social engineering, which means the attack is in place. The only answer here is B to reduce the risk of the credential attack. A is the best to prevent the attack.
upvoted 2 times
...
examdj101j
1 year ago
Selected Answer: B
B.) Implement two-factor authentication, (Another question may say multi-factor authentication) A.) Helps to prevent social engineering attacks, not really helpful in a successful attack because at this point the security awareness training failed for this user. C.) Block access to social media (Not helpful) D.) Enforce role based access control (Yes helpful), their access would be restricted but they would still have access. (With B, the Attacker still has to succeed in completing the multifactor authentication process). This options reduces the risk over the others.
upvoted 1 times
...
Agamennore
1 year, 8 months ago
Selected Answer: A
Only security awareness against social engineering
upvoted 2 times
...
AaronS1990
1 year, 8 months ago
Selected Answer: A
Preventing Social engineering attacks is mitigated by awareness training
upvoted 1 times
...
Saisharan
1 year, 9 months ago
Option A
upvoted 1 times
...
CrackyPatch
1 year, 9 months ago
Selected Answer: A
A. Conduct security awareness training
upvoted 3 times
...
chanke
1 year, 10 months ago
Selected Answer: A
For social engineering attacks one of the best ways it to conduct security awareness training
upvoted 3 times
...
SecHodler
2 years ago
Selected Answer: B
Attack is already successful, security awareness training is preventative, B 2FA would help reduce risk if social engineering attack is successful to get helpdesk password.
upvoted 4 times
Dravidian
2 years ago
MFA has nothing to do with social engineering. Also, question is asking about reducing the risks not next steps after an attack.
upvoted 5 times
Salilgen
1 year, 1 month ago
Question is asking about reducing the risks after a successful attack. It is the next step
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago