Skip to content

CS Professional · Internal and Forensic Audit · Emerging Issues and Challenges

During a review at Kaveri Pharma Ltd, an internal auditor learns that employees received an email appearing to come from the CFO asking them to urgently share their banking portal passwords, and several complied. Which type of cyber threat is this, and which preventive measure is most relevant?

This is phishing, a social engineering attack in which a fake email impersonating a senior officer tricks staff into revealing credentials. The most relevant preventive measure is regular security awareness training with clear reporting procedures, because the weakness lies in human behaviour.

  1. ADenial-of-service attack; increasing server bandwidth
  2. BPhishing; periodic security awareness training and reporting proceduresCorrect
  3. CRansomware; offline backup of files
  4. DSQL injection; input validation in the database

Explanation

A deceptive email impersonating a senior officer to obtain credentials is phishing (social engineering). The human factor is the weakness, so awareness training and clear reporting channels are most relevant. Backups address ransomware and input validation addresses SQL injection, which are not involved here.

Did you get it right without looking?

One question tells you little. A timed set on Emerging Issues and Challenges shows your real accuracy, how long you take and where you lose marks.

More Emerging Issues and Challenges questions