CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 245


A new employee formally reported suspicious behavior to the organization security team. The report claims that someone not affiliated with the organization was inquiring about the member's work location, length of employment, and building access controls. The employee's reporting is MOST likely the result of which of the following?

Show Answer
Correct Answer: B

The correct answer is security awareness. Security awareness training educates employees on how to recognize and respond to potential security threats. The new employee's ability to identify the suspicious behavior and report it to the organization security team indicates that they have been trained to be vigilant about security issues. This training is aimed at increasing the likelihood that employees will notice and report any suspicious activities, thus enhancing the overall security posture of the organization.

Discussion

15 comments
Sign in to comment
Cww1Option: B
Sep 12, 2022

I think this is B, the employee is reporting the phising attempt due to security awareness training

stickerbush1970Option: B
Sep 14, 2022

Agree with B

franbarproOption: B
Oct 22, 2022

Sounds like the new guy been paying attention during that awareness training.

ygcOption: B
Sep 13, 2022

I agree with B.

BDSecOption: B
Sep 24, 2022

Also agree with B

The_Black_OneOption: B
Oct 18, 2022

The answer is B. The employee reported this issue because of their level of security awareness.

byolarOption: B
Oct 2, 2022

The correct answer is B without a doubt.

OROROption: B
Oct 10, 2022

B is the answer

oudmasterOption: B
Dec 16, 2022

his report indicate he has high level of security awareness.

DJOEKOption: B
Jan 11, 2023

Security awareness is a program that provides education and training to employees and other individuals within an organization to increase their understanding of security risks and to help them identify and respond to potential security threats. By providing training and education on security awareness, organizations can increase the likelihood that employees will identify and report potential security threats, such as the suspicious behavior described in the scenario.

jackdryan
May 13, 2023

B is correct

pete79Option: C
Feb 9, 2024

Because phishing has taken place. Without attempt to phish, security awareness would have not result in report.

BP_lobsterOption: B
Nov 17, 2022

Phishing alone does not equal a higher reporting likelihood. Phishing + Security Awareness does.

74gjd_37Option: B
Sep 24, 2023

The employee's reporting is most likely the result of security awareness. The employee recognized the suspicious behavior and knew to report it to the organization security team. This shows that the employee had been trained to be aware of security risks and to report them promptly.

e58c193Option: B
Apr 4, 2024

Poorly worded question, what happened was a phish the reason he reported it was his security awareness. Still undecided on which one is correct.

TheManiacOption: B
May 18, 2024

Phishing is clearly there. Would that itself result the reporting? NO Security awareness of the user has resulted it being reported. New employee part can also be tricky but companies let new employees to get security awareness training on their onboarding process. This is another little indicator for it.