Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresHard
A security auditor is performing a post-incident review following a successful phishing attack that led to data exfiltration. The review identifies that while the organization had an up-to-date incident response plan, employees were unaware of the specific steps to report a suspicious email or whom to contact outside of business hours. This scenario indicates a weakness in which area of the security program?
- AThe clarity of the business continuity plan.
- BThe technical controls implemented for email filtering.
- CThe scope of the disaster recovery procedures.
- DThe effectiveness of security awareness and training.
Show answer & explanationAnswer & explanation
Correct answer: D. The effectiveness of security awareness and training.
Despite having an incident response plan, the employees' lack of knowledge about how to report suspicious emails or whom to contact indicates a failure in disseminating and reinforcing critical information, which is a core function of security awareness and training.
Why the other options are wrong
- A. Business continuity deals with maintaining operations, not specific incident reporting by employees.
- B. While technical controls are important, the issue here is human action/knowledge, not the filter itself.
- C. Disaster recovery focuses on restoring systems after a major event, not on early incident reporting mechanisms.
Security Awareness Effectiveness
The degree to which security awareness training successfully changes employee behavior and knowledge to reduce human-related security risks.
- Requires clear communication and reinforcement.
- Measured by changes in employee actions and incident rates.
- Essential for proactive threat mitigation.
Memory trick: Humans are the first line of defense, if they know what to do.