EC-Council Certified Ethical Hacker (CEH) v12Social EngineeringHard

A cybersecurity team is implementing comprehensive social engineering countermeasures within their organization. They have focused on technical controls, such as advanced spam filters and email authentication protocols. However, they observe that employees are still falling victim to sophisticated phishing attacks, particularly those involving urgent requests from seemingly legitimate internal departments. Which countermeasure is most likely to be missing or insufficient in their current strategy, leading to these continued successful attacks?

  1. ADeploying a Network Access Control (NAC) solution.
  2. BConducting regular, mandatory security awareness training for all employees.
  3. CEnhancing endpoint detection and response (EDR) capabilities.
  4. DImplementing a robust Intrusion Detection System (IDS)
Show answer & explanation

Correct answer: B. Conducting regular, mandatory security awareness training for all employees.

While technical controls like spam filters and email authentication are crucial, sophisticated phishing attacks often exploit human psychology, urgency, and trust. An IDS, NAC, or EDR primarily address network or endpoint security post-compromise or during access, not the initial human vulnerability. Regular, mandatory security awareness training is essential to educate employees on recognizing and reporting social engineering tactics, especially those leveraging urgency and internal departmental pretexts.

Why the other options are wrong

  • A. NAC controls who can access the network but doesn't prevent an authenticated user from falling for a phishing scam.
  • C. EDR focuses on detecting and responding to threats on endpoints, which is reactive after a compromise, not proactive against the initial social engineering attempt.
  • D. An IDS detects malicious activity but doesn't prevent the initial human error that allows social engineering to succeed.

Security Awareness Training

Educational programs designed to inform employees about cybersecurity threats, best practices, and how to recognize and respond to attacks, particularly social engineering.

  • Focuses on the human element of security.
  • Teaches recognition of phishing, pretexting, etc.
  • Crucial for building a 'human firewall'.

Memory trick: Train your people to be the strongest shield.

More Social Engineering questions