TOC Cybersecurity & Risk Management 2 — Questions and Answers
Question 1: An HR manager receives an urgent email appearing to be from the CEO requesting an immediate wire transfer of employee payroll data. This is an example of which attack type?
- Ransomware
- Business email compromise (BEC) (Correct answer)
- Distributed denial of service
- SQL injection
Correct answer: Business email compromise (BEC)
Business email compromise (BEC) involves attackers impersonating executives to manipulate employees into fraudulent actions.
Question 2: Under CCPA, which category of employee data requires the highest level of protection?
- Job title and department
- Work email address
- Social Security numbers and financial account information (Correct answer)
- Start date and work schedule
Correct answer: Social Security numbers and financial account information
Social Security numbers and financial account information are classified as sensitive personal information under CCPA, requiring heightened protection.
Question 3: A talent optimization consultant is assessing risk from a recently terminated employee who had admin access to the HRIS. What is the FIRST action that should have occurred?
- Notify law enforcement
- Revoke all system access immediately upon termination (Correct answer)
- Conduct a forensic audit of all their activity
- Change the company Wi-Fi password
Correct answer: Revoke all system access immediately upon termination
Immediate access revocation upon termination is the critical first step to prevent insider threats from former employees.
Question 4: Which framework is most commonly used by organizations to structure their cybersecurity risk management programs?
- DISC behavioral model
- NIST Cybersecurity Framework (Correct answer)
- Predictive Index methodology
- Kirkpatrick evaluation model
Correct answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework provides a structured approach to identifying, protecting, detecting, responding to, and recovering from cyber threats.
Question 5: An organization discovers that an employee has been sharing confidential compensation data via personal email. This is best classified as which type of risk?
- External threat
- Malicious insider threat
- Negligent insider threat (Correct answer)
- Supply chain attack
Correct answer: Negligent insider threat
A negligent insider threat involves an employee who inadvertently or carelessly exposes sensitive data without malicious intent.
Question 6: Which data classification level typically applies to aggregated employee performance review data stored in an HRIS?
- Public
- Confidential (Correct answer)
- Top Secret
- Unrestricted
Correct answer: Confidential
Employee performance data is confidential because its disclosure could harm individuals or the organization but is not at the highest classification tier.
Question 7: A company wants to reduce the risk of credential stuffing attacks against its talent management platform. Which control is MOST effective?
- Increasing password minimum length to 8 characters
- Implementing multi-factor authentication (MFA) (Correct answer)
- Adding a CAPTCHA to the login page
- Disabling password reset functionality
Correct answer: Implementing multi-factor authentication (MFA)
MFA prevents credential stuffing attacks by requiring a second verification factor even when passwords are compromised.
An HR manager receives an urgent email appearing to be from the CEO requesting an immediate wire transfer of employee payroll data.
This is an example of which attack type?