New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CRISC Exam - Topic 6 Question 102 Discussion

Actual exam question for Isaca's CRISC exam
Question #: 102
Topic #: 6
[All CRISC Questions]

An unauthorized individual has socially engineered entry into an organization's secured physical premises. Which of the following is the BEST way to prevent future occurrences?

Show Suggested Answer Hide Answer
Suggested Answer: B

Social engineering is a technique that involves manipulating or deceiving people into performing actions or divulging information that may compromise the security of an organization or its data12.

Entry into an organization's secured physical premises is a form of physical access that allows an unauthorized individual to access, steal, or damage the organization's assets, such as equipment, documents, or systems34.

The best way to prevent future occurrences of social engineering entry into an organization's secured physical premises is to conduct security awareness training, which is an educational program that aims to equip the organization's employees with the knowledge and skills they need to protect the organization's data and sensitive information from cyber threats, such as hacking, phishing, or other breaches56.

Security awareness training is the best way because it helps the employees to recognize and resist the common and emerging social engineering techniques, such as tailgating,impersonation, or pretexting, that may be used by the attackers to gain physical access to the organization's premises56.

Security awareness training is also the best way because it fosters a culture of security and responsibility among the employees, and encourages them to follow the best practices andpolicies for physical security, such as locking the doors, verifying the identity of visitors, or reporting any suspicious activities or incidents56.

The other options are not the best way, but rather possible measures or controls that may supplement or enhance the security awareness training. For example:

Employing security guards is a measure that involves hiring or contracting professional personnel who are trained and authorized to monitor, patrol, and protect the organization's premises from unauthorized access or intrusion78.However, this measure is not the best way because it may not be sufficient or effective to prevent or deter all types of social engineering attacks, especially if the attackers are able to bypass, deceive, or coerce the security guards78.

Installing security cameras is a control that involves using electronic devices that capture and record the visual images of the organization's premises, and provide evidence or alerts of any unauthorized access or activity . However, this control is not the best way because it is reactive rather than proactive, and may not prevent or stop the social engineering attacks before they cause any harm or damage to the organization .

Requiring security access badges is a control that involves using physical or electronic cards that identify and authenticate the employees or authorized visitors who are allowed to enter the organization's premises, and restrict or deny the access to anyone else . However, this control is not the best way because it may not be foolproof or reliable to prevent or detect the social engineering attacks, especially if the attackers are able to steal, forge, or clone the security access badges .Reference=

1: What is Social Engineering?| Types & Examples of Social Engineering Attacks1

2: Social Engineering: What It Is and How to Prevent It | Digital Guardian2

3: What is physical Social Engineering and why is it important?- Integrity3603

4: What Is Tailgating (Piggybacking) In Cyber Security?- Wlan Labs4

5: What Is Security Awareness Training and Why Is It Important?- Kaspersky5

6: Security Awareness Training - Cybersecurity Education Online | Proofpoint US6

7: Security Guard - Wikipedia7

8: Security Guard Services - Allied Universal8

Security Camera - Wikipedia

Security Camera Systems - The Home Depot

Access Badge - Wikipedia

Access Control Systems - HID Global


Contribute your Thoughts:

0/2000 characters
Miss
2 months ago
Security guards can be a great deterrent too!
upvoted 0 times
...
Carma
2 months ago
Really? I doubt training alone will fix this.
upvoted 0 times
...
Noelia
3 months ago
Totally agree, people need to know the risks.
upvoted 0 times
...
Ty
3 months ago
Cameras are cool, but they won't stop social engineering.
upvoted 0 times
...
Jovita
3 months ago
Security awareness training is a must!
upvoted 0 times
...
Janna
3 months ago
I feel like conducting security awareness training is important, but I’m leaning towards requiring access badges as the most direct solution.
upvoted 0 times
...
Yun
4 months ago
I practiced a similar question where installing security cameras was mentioned, but I wonder if they actually prevent entry or just record it.
upvoted 0 times
...
Aretha
4 months ago
I think requiring security access badges is crucial, but I also feel like security guards could deter unauthorized entry effectively.
upvoted 0 times
...
Fannie
4 months ago
I remember discussing how security awareness training can really help employees recognize social engineering tactics, but I'm not sure if it's the best option here.
upvoted 0 times
...
Elbert
4 months ago
I've got this! The best way to prevent future occurrences of unauthorized physical access is to require security access badges. That way, you can control and monitor who is entering the premises.
upvoted 0 times
...
Arlette
4 months ago
Okay, let's see. Security guards, security awareness training, security cameras, or security access badges. I think the key is to find the solution that provides the most robust and layered security.
upvoted 0 times
...
Terrilyn
5 months ago
Hmm, I'm a bit unsure about this one. I know physical security is important, but I'm not sure which of these options would be the best approach.
upvoted 0 times
...
Helaine
5 months ago
This seems like a straightforward physical security question. I'll need to carefully consider the options and think about the most comprehensive solution.
upvoted 0 times
...
Amina
5 months ago
I'm with Sarah on this one. People are the weakest link, so training is crucial.
upvoted 0 times
...
Alex
5 months ago
Installing security cameras could also help in preventing future occurrences.
upvoted 0 times
...
Thea
5 months ago
I disagree, I believe conducting security awareness training is more effective.
upvoted 0 times
...
Lucy
6 months ago
I think the best way is to employ security guards.
upvoted 0 times
...
Sarah
7 months ago
Security awareness training is key. Gotta educate the employees before they get duped again.
upvoted 0 times
...
Jonell
7 months ago
Access badges all the way! That'll keep those pesky social engineers out for good.
upvoted 0 times
Socorro
5 months ago
Access badges are definitely the way to go. It's a simple but effective solution.
upvoted 0 times
...
...

Save Cancel