Module Question 10
- Define “social engineering” and provide three examples (e.g., pretexting, baiting).
- What are the key components of a good security awareness training program for employees?
- How can a simple “clean desk” policy contribute to the overall security of a business?
Status : 100%
Keterangan : saya sudah mengerjakan tugas ini dengan baik dan benar
Bukti :
- Social engineering is a type of cyberattack that manipulates people into revealing confidential information or performing actions that compromise security.
Examples include:
- Pretexting: An attacker pretends to be someone trustworthy (e.g., IT staff) to obtain sensitive data.
- Baiting: Offering something enticing (like a free USB or download) to trick users into exposing data or installing malware.
- Phishing: Sending fake emails or messages that appear legitimate to steal login credentials or financial information.
2. A good security awareness training program should include:
- Regular training sessions on common threats (phishing, malware, social engineering)
- Real-world simulations (e.g., phishing tests)
- Clear security policies and guidelines
- Easy reporting mechanisms for suspicious activities
- Continuous updates to keep up with new threats
3. A clean desk policy helps prevent sensitive information (like documents, passwords, or devices) from being left exposed. By keeping workspaces clear and securing materials when not in use, businesses reduce the risk of unauthorized access, data leaks, and information theft.
