An organization experienced a security attack. A hacker accessed a system using login information gathered from social media sites. The incident was identified quickly and systems were restored without significant loss.
Which type of control should be improved?
The scenario says the attack was identified quickly and systems were restored without significant loss. That means detection and corrective response were relatively effective. The weakness was that the attacker was able to gain access in the first place.
Therefore, the type of control needing improvement is prevention. This could include stronger identity protection, user awareness, multi-factor authentication, credential monitoring, and better social engineering resistance.
D is correct because the issue occurred before the detection stage; the preventive safeguards were insufficient.
=========
Currently there are no comments in this discussion, be the first to comment!