Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresHard

A security auditor is performing a post-incident review following a successful phishing attack that led to data exfiltration. The review identifies that while the organization had an up-to-date incident response plan, employees were unaware of the specific steps to report a suspicious email or whom to contact outside of business hours. This scenario indicates a weakness in which area of the security program?

  1. AThe clarity of the business continuity plan.
  2. BThe technical controls implemented for email filtering.
  3. CThe scope of the disaster recovery procedures.
  4. DThe effectiveness of security awareness and training.
Show answer & explanation

Correct answer: D. The effectiveness of security awareness and training.

Despite having an incident response plan, the employees' lack of knowledge about how to report suspicious emails or whom to contact indicates a failure in disseminating and reinforcing critical information, which is a core function of security awareness and training.

Why the other options are wrong

  • A. Business continuity deals with maintaining operations, not specific incident reporting by employees.
  • B. While technical controls are important, the issue here is human action/knowledge, not the filter itself.
  • C. Disaster recovery focuses on restoring systems after a major event, not on early incident reporting mechanisms.

Security Awareness Effectiveness

The degree to which security awareness training successfully changes employee behavior and knowledge to reduce human-related security risks.

  • Requires clear communication and reinforcement.
  • Measured by changes in employee actions and incident rates.
  • Essential for proactive threat mitigation.

Memory trick: Humans are the first line of defense, if they know what to do.

More Security Policies and Procedures questions