A penetration tester, who did not have an access badge, managed to follow a group of employees through multiple badged-access doors and into the data center without being stopped. The tester mentions this finding during the after-action review with the Chief Information Security Officer (CISO). Which of the following issues should the CISO address as a result of this finding?
Social engineering.
The scenario highlights a penetration tester gaining unauthorized access by following employees, which exemplifies a social engineering tactic. This indicates a failure in security protocols that should prevent unauthorized individuals from exploiting human behavior to bypass physical security measures.
Role-based access control (RBAC) pertains to granting access to resources based on an individual's role within an organization. While this is an important security measure, the situation described does not primarily relate to access permissions based on roles but rather to exploiting social interactions. Therefore, addressing RBAC would not directly resolve the issue of human factors allowing unauthorized access.
Shoulder surfing involves observing someone’s confidential information, typically over their shoulder, such as passwords or PINs. This scenario does not involve the tester observing credentials but instead focuses on physical access granted through social interaction. Thus, while shoulder surfing is a security concern, it does not apply to the circumstances described.
An insider threat refers to risks posed by individuals within the organization who have insider information or access. Although the tester exploited employee behavior, the main issue centers around the manipulation of social dynamics rather than an intentional act by an insider. Therefore, addressing insider threats does not directly tackle the breach of security demonstrated in this case.
Social engineering is the manipulation of people into performing actions or divulging confidential information, which is exactly what occurred when the penetration tester followed employees into restricted areas. This indicates a need for enhanced training and awareness programs to ensure personnel recognize and respond appropriately to potential breaches of security protocols.
The penetration tester's ability to gain unauthorized access through social engineering highlights a significant vulnerability in the organization's security practices. This incident underscores the importance of training employees to recognize and prevent social engineering tactics, ensuring that access control measures are not solely reliant on physical badges but also include vigilance against manipulation and exploitation of the human element.
Related Questions
View allA company receives an alert that a network device vendor, which is wid...
A security administrator must use a strategy to protect the company's...
Which of the following technologies must be used in an organization th...
Which of the following risk management strategies describes applying a...
A security practitioner completes a vulnerability assessment on a comp...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus 501 Practice Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations