CAF-3 · Chapter 17 · Question 11 of 15
To ensure employees truly understand the theoretical risk management policies, the IT department periodically sends out fake, deceptive emails to see if staff will click on malicious links. This highly effective best practice is known as:
Test yourself: pick an answer
Reveal answer & explanation
Correct answer: C) Conducting simulations or mock phishing campaigns
Explanation
Using simulations or drills, such as mock phishing campaigns, is a best practice to practically assess employees' understanding of risk management and security policies in real-world scenarios
More Best Practices & Implementation Strategies MCQs
- Q13How does Information and Communication Technology (ICT) essentially act as a "double-edged sword" for modern organizations?
- Q14In the context of risk identification, what specific advantage do "Automated Vulnerability Scanners" provide over manual IT audits?
- Q15The overarching conclusion of integrating ICT into risk management is that it enables organizations to move from a reactive posture…
- Q1What is the primary role of Information and Communication Technology (ICT) in modern risk management?
- Q2Why has risk management in modern organizations expanded far beyond traditional, manual approaches?
