Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresMedium
A new employee is onboarding at a tech company. During their initial security training, they are taught about phishing awareness, safe browsing habits, and the company's policy on reporting suspicious emails. Which of the following is the primary goal of this type of training?
- ATo delegate all security responsibilities to end-users.
- BTo transform employees into the organization's 'human firewall'.
- CTo reduce the risk of human error leading to security incidents.
- DTo ensure compliance with external regulatory frameworks.
Show answer & explanationAnswer & explanation
Correct answer: C. To reduce the risk of human error leading to security incidents.
Security awareness training aims to educate employees about common threats and best practices, thereby reducing the likelihood that they will make mistakes that could lead to security incidents.
Why the other options are wrong
- A. Training empowers users but doesn't shift all responsibility from the security team.
- B. While a 'human firewall' is a metaphor for empowered users, the core goal is to mitigate human-caused risks.
- D. While training contributes to compliance, its primary goal is direct risk mitigation through behavior change.
Security Awareness Training
Programs designed to educate employees about cybersecurity threats, organizational policies, and best practices to protect sensitive information and systems.
- Aims to change user behavior to be more security-conscious.
- Covers topics like phishing, malware, password hygiene.
- Is a continuous process, not a one-time event.
Memory trick: Training builds a smart shield against digital dangers.