37. While updating the security awareness training, a security analyst wants to address issues created if vendors' email accounts are compromised. Which of the following recommendations should the security analyst include in the training?

Answer: D

Explanation:

Be alert to unexpected requests from familiar email addresses.

Training should emphasize the importance of being vigilant about unexpected requests, even from known contacts, as compromised email accounts can lead to social engineering attacks and fraudulent activities.

A) Refrain from clicking on images included in emails from new vendors.

While this option provides some level of caution, it is not comprehensive enough to address the broader issue of vendor email account compromises. Users must also be aware that legitimate-looking emails from familiar contacts can still pose threats if those accounts are compromised.

B) Delete emails from unknown service provider partners.

This recommendation may promote unnecessary caution and could prevent users from accessing legitimate communications. Instead of deleting emails outright, users should be trained to scrutinize the content of such emails for potential threats, making this option less effective.

C) Require that invoices be sent as attachments.

This suggestion does not directly address the issue of email account compromises and could create additional friction in legitimate vendor communications. The focus should be on recognizing and responding to suspicious activity rather than altering the communication format.

D) Be alert to unexpected requests from familiar email addresses.

This option is the most appropriate, as it emphasizes the need for vigilance even when emails appear to come from known contacts. It highlights the risk of compromised accounts leading to deceptive requests that could result in security breaches.

Conclusion

The correct answer emphasizes the critical need for awareness regarding unexpected requests from familiar contacts, as compromised email accounts can easily lead to security vulnerabilities. Other options either fail to address the specific threats posed by email account compromises or could hinder effective communication in legitimate vendor interactions. Therefore, training should prioritize the need for vigilance in all email communications.