While updating the security awareness training, a security analyst wants to address issues created if vendors' email accounts are compromised. Which of the following recommendations should the security analyst include in the training?
Be alert to unexpected requests from familiar email addresses.
This recommendation is crucial as attackers often exploit compromised accounts of known contacts to send malicious requests or links. By highlighting the importance of vigilance even with familiar contacts, the training can help prevent potential phishing attacks that bypass traditional security measures.
While caution is warranted when dealing with new vendors, focusing solely on images does not address the broader issue of email account compromise. Attackers can use various tactics beyond images, such as links or attachments, making this recommendation insufficient for comprehensive security awareness.
Deleting emails from unknown partners can lead to missed important communications or legitimate business opportunities. Instead of outright deletion, the training should encourage users to verify the authenticity of such emails through different channels, ensuring they do not overlook crucial information.
This recommendation may address a specific scenario but does not encompass the broader implications of email security. Attackers can still send malicious attachments, and simply requiring attachments may create a false sense of security rather than fostering a comprehensive understanding of potential threats.
Awareness of unexpected requests from familiar email addresses is a vital training component, as it directly addresses the risks associated with compromised accounts. By focusing on this recommendation, the security analyst can equip employees to recognize and mitigate potential phishing attempts, thereby enhancing overall organizational security. It is essential to cultivate a culture of vigilance that extends beyond specific email practices to encompass all forms of communication.
Related Questions
View allA security analyst is evaluating a SaaS application that the human res...
Which of the following scenarios is a warning sign specific to insider...
A company receives an alert that a network device vendor, which is wid...
Which of the following is used to calculate the impact to an organizat...
A user receives an aggressive text from an unknown sender who is deman...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus 501 Practice Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations