While updating the security awareness training, a security analyst wants to address issues created if vendors' email accounts are compromised. Which of the following recommendations should the security analyst include in the training?
Be alert to unexpected requests from familiar email addresses.
Unexpected requests from familiar email addresses can indicate a compromised account, highlighting the importance of vigilance even when the sender appears legitimate. This recommendation encourages users to critically evaluate all communications, regardless of the perceived trustworthiness of the sender.
While caution is warranted when interacting with emails from new vendors, this recommendation does not directly address the risks associated with compromised accounts. Compromised familiar accounts could also contain images that are safe, so merely avoiding images does not provide comprehensive protection against phishing attempts or other malicious activities.
Deleting emails from unknown service provider partners may prevent interaction with potentially harmful emails, but it does not adequately address the risk posed by compromised familiar accounts. This approach lacks a proactive security strategy, as it disregards the possibility of legitimate communication that could be important for security awareness and response.
Requiring invoices to be sent as attachments does not address the core issue of email account compromise. Attackers can still send malicious attachments from familiar accounts, making this recommendation insufficient as a standalone security measure. The focus should instead be on recognizing suspicious behavior regardless of how invoices are delivered.
In addressing the risks associated with vendor email account compromises, it is essential to remain vigilant about unexpected requests from familiar email addresses. This strategy empowers users to identify potential phishing attempts and malicious activities, thus enhancing overall organizational security. While other recommendations may offer some level of caution, they do not specifically tackle the vulnerabilities posed by compromised accounts, making awareness of unexpected requests the most critical focus in training.
Related Questions
View allA site reliability engineer is designing a recovery strategy that requ...
Which of the following is the best safeguard to protect against an ext...
Which of the following is a use of CVSS?
A Chief Information Security Officer is developing procedures to guide...
Which of the following security concepts is being followed when implem...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
CompTIA Security Plus Simulation Questions
CompTIA Security Plus 501 Practice Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations