9. A penetration tester, who did not have an access badge, managed to follow a group of employees through multiple badged-access doors and into the data center without being stopped. The tester mentions this finding during the after-action review with the Chief Information Security Officer (CISO). Which of the following issues should the CISO address as a result of this finding?
Answer: D
Social engineering
The CISO should address social engineering as a result of the tester's ability to gain unauthorized access to the data center by following employees through badged-access doors. This incident highlights the potential vulnerabilities in the organization's security practices related to human behavior and awareness.
A) Role-based access
Role-based access is a method of restricting system access to authorized users based on their roles within the organization. While it is important for securing sensitive areas, this incident specifically demonstrates a failure in physical security protocols and employee vigilance, rather than issues with the role-based access controls themselves.
B) Shoulder surfing
Shoulder surfing refers to the act of observing someone’s private information without their consent, typically in the context of digital devices. Although it is a security concern, it is not relevant to this scenario, where the tester's unauthorized access was achieved through physical observation and following others rather than directly observing sensitive information.
C) Insider threat
An insider threat involves individuals within the organization who misuse their access to harm the organization. While the tester's actions could be seen as an insider threat, in this context, the main issue is not about an insider but rather about the exploitation of social dynamics and lack of security awareness among employees.
D) Social engineering
Social engineering involves manipulating individuals into divulging confidential information or enabling unauthorized access. This incident exemplifies social engineering tactics, as the tester successfully infiltrated the secure area by leveraging the behavior of employees, indicating a critical need for training and awareness programs to mitigate such risks.
Conclusion
The correct answer, social engineering, directly addresses the root cause of the security breach in this scenario, emphasizing the need for improved employee awareness and training. Other options, while relevant to security in general, do not specifically pertain to the method by which the tester gained access, thereby failing to address the core issue effectively.