While updating the security awareness training, a security analyst wants to address issues created if vendors' email accounts are compromised. Which of the following recommendations should the security analyst include in the training?
Be alert to unexpected requests from familiar email addresses.
This recommendation is crucial as attackers often exploit compromised accounts of known contacts to send malicious requests or links. By highlighting the importance of vigilance even with familiar contacts, the training can help prevent potential phishing attacks that bypass traditional security measures.
While caution is warranted when dealing with new vendors, focusing solely on images does not address the broader issue of email account compromise. Attackers can use various tactics beyond images, such as links or attachments, making this recommendation insufficient for comprehensive security awareness.
Deleting emails from unknown partners can lead to missed important communications or legitimate business opportunities. Instead of outright deletion, the training should encourage users to verify the authenticity of such emails through different channels, ensuring they do not overlook crucial information.
This recommendation may address a specific scenario but does not encompass the broader implications of email security. Attackers can still send malicious attachments, and simply requiring attachments may create a false sense of security rather than fostering a comprehensive understanding of potential threats.
Awareness of unexpected requests from familiar email addresses is a vital training component, as it directly addresses the risks associated with compromised accounts. By focusing on this recommendation, the security analyst can equip employees to recognize and mitigate potential phishing attempts, thereby enhancing overall organizational security. It is essential to cultivate a culture of vigilance that extends beyond specific email practices to encompass all forms of communication.
Related Questions
View allA penetration tester is testing the security of a building's alarm sys...
Which of the following best describes a threat actor who can coordinat...
Which of the following is the greatest advantage that network segmenta...
A penetration tester, who did not have an access badge, managed to fol...
A systems administrator is concerned about vulnerabilities within clou...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus 501 Practice Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations