Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 422 discussion

Actual exam question from Isaca's CISM
Question #: 422
Topic #: 1
[All CISM Questions]

Which of the following is the BEST way to reduce the risk associated with a successful social engineering attack targeting help desk staff?

  • A. Conduct security awareness training
  • B. Implement two-factor authentication
  • C. Block access to social media sites
  • D. Enforce role based access to help desk systems
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Raven89
2 weeks, 6 days ago
social eng is not only phishing ! Think to a phone call, tailgaiting etc .... it is always training A
upvoted 1 times
...
03allen
6 months, 1 week ago
Selected Answer: B
It says a successful social engineering, which means the attack is in place. The only answer here is B to reduce the risk of the credential attack. A is the best to prevent the attack.
upvoted 2 times
...
examdj101j
7 months, 1 week ago
Selected Answer: B
B.) Implement two-factor authentication, (Another question may say multi-factor authentication) A.) Helps to prevent social engineering attacks, not really helpful in a successful attack because at this point the security awareness training failed for this user. C.) Block access to social media (Not helpful) D.) Enforce role based access control (Yes helpful), their access would be restricted but they would still have access. (With B, the Attacker still has to succeed in completing the multifactor authentication process). This options reduces the risk over the others.
upvoted 1 times
...
Agamennore
1 year, 2 months ago
Selected Answer: A
Only security awareness against social engineering
upvoted 1 times
...
AaronS1990
1 year, 3 months ago
Selected Answer: A
Preventing Social engineering attacks is mitigated by awareness training
upvoted 1 times
...
Saisharan
1 year, 4 months ago
Option A
upvoted 1 times
...
CrackyPatch
1 year, 4 months ago
Selected Answer: A
A. Conduct security awareness training
upvoted 3 times
...
chanke
1 year, 4 months ago
Selected Answer: A
For social engineering attacks one of the best ways it to conduct security awareness training
upvoted 2 times
...
richck102
1 year, 4 months ago
A. Conduct security awareness training
upvoted 3 times
...
SecHodler
1 year, 7 months ago
Selected Answer: B
Attack is already successful, security awareness training is preventative, B 2FA would help reduce risk if social engineering attack is successful to get helpdesk password.
upvoted 4 times
Dravidian
1 year, 6 months ago
MFA has nothing to do with social engineering. Also, question is asking about reducing the risks not next steps after an attack.
upvoted 5 times
Salilgen
8 months, 3 weeks ago
Question is asking about reducing the risks after a successful attack. It is the next step
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...