A Chief Security Officer (CSO) is concerned about the number of successful ransomware attacks that have hit the company. The data indicates most of the attacks came through a fake email. The company has added training, and the CSO now wants to evaluate whether the training has been successful. Which of the following should the CSO implement?
The correct answer is: A. Simulating a spam campaign
To evaluate whether training on email security and phishing awareness has been effective, the best approach is to simulate a phishing or spam campaign. This involves sending fake but realistic phishing emails to employees to test their responses and measure the success of the training.
Why the other options are incorrect:
Conducting a sanctioned vishing attack:
Performing a risk assessment:
Executing a penetration test:
No Payment Cards Needed
Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.
You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams