Domain 5: Protection of Information Assets7 min · 3 questions

Security Awareness and Attack Methods

The strongest controls are bypassed by fooling a person. The exam tests why awareness training is the control for social engineering, and how to recognise the common attack methods.

What this makes you able to do

Evaluate whether people are prepared to resist social engineering, and recognise common attack methods.

By the end you can

  • Explain why the human is often the weakest link.
  • Identify security awareness training as the control for social engineering.
  • Recognise common attack methods and their impact.

Transcript

Security awareness and attack methods. Most of Domain five is technology. This lesson is about the human, who is often the way in.

The scene. The organisation has spent years hardening its technology: firewalls, encryption, patching, monitoring. Then an attacker phones the service desk, claims to be a stressed executive locked out before a board meeting, and is given a password reset over the phone. No control was broken. A person was persuaded. Every technical defence was intact, and none of them was aimed at the point that failed.

Attackers go where the defences are thinnest, and that is often the person, not the system. Social engineering manipulates people into divulging information or taking actions that compromise security, deliberately bypassing technical controls by exploiting trust, urgency, fear or authority. The service-desk call is a classic: the technology never came into it.

Because the target is human, the primary control is human: security awareness training. Training helps people recognise manipulation, verify identities, resist pressure, and report suspicious approaches. Another firewall does nothing here; teaching the service desk to verify a caller before resetting a password does.

So when a question asks the most effective control against phishing or social engineering, it is awareness training, because these attacks aim at people rather than technology. Not another firewall. Training.

The exam expects you to recognise the common methods and what they target. First, phishing, and targeted spear-phishing: fraudulent messages that trick people into revealing credentials or clicking malicious links. The most common entry point.

Second, malware and ransomware: malicious software; ransomware encrypts data and demands payment, attacking availability.

And then denial of service, flooding a system to make it unavailable; man-in-the-middle, intercepting communications, defeated by encryption in transit; and credential theft and insider threat, stolen or misused legitimate access, which least privilege and monitoring contain.

A useful skill: match the attack to the security property it undermines. Phishing and credential theft threaten confidentiality and access; ransomware and denial of service threaten availability. Naming the property is often what a question is really testing.

Ransomware deserves a moment because it ties back to Domain four. Its primary impact is on availability, it denies access to data by encrypting it. The control that most directly enables recovery without paying is reliable, tested, offsite backups the ransomware cannot reach, exactly the restoration-tested, geographically separated backups from the resilience lessons.

So two controls, two jobs. Awareness training reduces the chance of the initial infection; good backups mean that if it happens, the organisation can restore rather than pay. Stronger encryption does not help, the problem is not secrecy but access.

So carry this away. Social engineering targets people and is countered by awareness training, not another technical layer, because the human is part of the attack surface. And connect each attack to the property it undermines and the control that answers it: ransomware attacks availability and is answered by tested backups; social engineering attacks trust and is answered by training.

Knowledge check
0 / 3
  1. 1.What is the MOST effective control against social engineering attacks such as phishing?

  2. 2.What best describes a social engineering attack?

  3. 3.A ransomware attack encrypts an organisation's files and demands payment. What is its PRIMARY impact, and what control most directly enables recovery without paying?

Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.