Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca AAISM Exam - Topic 1 Question 7 Discussion

Actual exam question for Isaca's AAISM exam
Question #: 7
Topic #: 1
[All AAISM Questions]

How can an organization BEST protect itself from payment diversions caused by deepfake attacks impersonating management?

Show Suggested Answer Hide Answer
Suggested Answer: D

AAISM's risk management framework stresses that the most effective defense against deepfake-enabled fraud, such as payment diversion, is resilient payment approval processes. This includes multi-step verification, segregation of duties, and independent confirmations for high-value transactions. Employee training, policies, or limiting payment frequency may reduce exposure, but they cannot guarantee prevention. Only process-based controls enforce structural safeguards that prevent fraudulent instructions from being executed, even if a deepfake impersonation attempt is successful.


AAISM Exam Content Outline -- AI Risk Management (Fraud and Deepfake Risk)

AI Security Management Study Guide -- Transactional Resilience and Controls

Contribute your Thoughts:

0/2000 characters
Leeann
1 day ago
I agree with D. Resilience in approvals is key to security.
upvoted 0 times
...
Linn
6 days ago
B seems too restrictive. Weekly payments could slow things down.
upvoted 0 times
...
Nada
11 days ago
B) won't stop the problem, just delays it.
upvoted 0 times
...
Shaunna
17 days ago
C) is a must-have in today's world!
upvoted 0 times
...
Veronika
22 days ago
Really? Weekly payments? That seems impractical.
upvoted 0 times
...
Cristy
27 days ago
D) is definitely the best option here.
upvoted 0 times
...
Carrol
2 months ago
A) sounds like a solid start!
upvoted 0 times
...
Doug
2 months ago
D) Definitely the way to go. Robust approval processes are key to preventing payment diversions.
upvoted 0 times
...
Phillip
2 months ago
C) A security policy on deepfakes is important, but it needs to be backed up by actual security measures.
upvoted 0 times
...
Emilio
2 months ago
Haha, B) Mandate payments once a week? That's like putting a band-aid on a bullet wound!
upvoted 0 times
...
Mary
2 months ago
A) Mandatory deepfake detection training is a good start, but it's not enough on its own.
upvoted 0 times
...
Deonna
2 months ago
D) Implement resilient payment approval processes. This is the best way to protect against deepfake attacks.
upvoted 0 times
...
Kip
3 months ago
Mandating weekly payments sounds a bit too restrictive. I feel like it could slow down operations without really addressing the deepfake issue.
upvoted 0 times
...
Beatriz
3 months ago
I remember a practice question about payment fraud, and I think issuing a security policy could be helpful, but it might not be enough on its own.
upvoted 0 times
...
Caprice
3 months ago
I'm not sure about the effectiveness of just training employees on deepfake detection. It seems like they could still fall for a convincing video.
upvoted 0 times
...
Naomi
3 months ago
Option D is the way to go. Strengthening the payment approval workflow is key - things like requiring multiple approvals, verifying identities through multiple channels, and having a clear escalation process. That's going to be the most effective defense against these kinds of attacks.
upvoted 0 times
...
Luisa
3 months ago
I'm leaning towards B. Limiting payments to once a week could really reduce the window of opportunity for a deepfake attack. Plus, it's a simple policy change that's easy to implement. The other options seem more complex.
upvoted 0 times
...
Leota
3 months ago
Definitely go with option D. Implementing a robust payment approval system with multiple layers of verification is the surest way to prevent diversions, even if a deepfake slips through. The other options are good but not as comprehensive.
upvoted 0 times
...
Tomas
4 months ago
I think A is crucial. Training helps everyone stay alert.
upvoted 0 times
...
Vi
4 months ago
I think option D makes the most sense since having robust approval processes could help catch any suspicious requests.
upvoted 0 times
...
Timothy
4 months ago
C is a good start, but it needs to be more than just a policy.
upvoted 0 times
...
Marguerita
4 months ago
D is the best option. Strong processes can prevent fraud effectively.
upvoted 0 times
...
Gary
5 months ago
I'm a bit confused by the options. Requiring training and issuing a policy seem like good first steps, but I'm not sure they're the "best" approach. Maybe the payment approval process is the way to go?
upvoted 0 times
...
Murray
5 months ago
Hmm, this is a tricky one. I think the key is to focus on the "best" part of the question - we need to find the most effective solution to protect against deepfake attacks.
upvoted 0 times
Tasia
4 months ago
I think A is crucial. Training helps everyone recognize deepfakes.
upvoted 0 times
...
...

Save Cancel