QuestionQ118

Technology and Security

An insurance company that handles its customers’ sensitive and personal information receives a high volume of telephone requests and electronic communications each day. Which of the following is MOST important to include in a risk-awareness training session for the customer service department?

  • A Identifying social engineering attacks
  • B Archiving sensitive information
  • C Understanding the importance of using a secure password
  • D Understanding the incident management process
Explanation

Customer service staff are frequent targets of social engineering because they receive unsolicited calls and electronic messages and may have access to sensitive customer data. Training them to identify impersonation, phishing, pretexting, and similar attacks helps prevent unauthorized disclosure and fraudulent requests.

Community Discussion

No comments yet. Be the first to start the discussion!