An enterprise security awareness trainer asks: 'In the context of AI-generated social engineering, what is the single most important question an employee should ask themselves before taking a financial or access action requested through any communication channel?'
- A.'Did I initiate this interaction, or am I responding to an inbound request?' - legitimate financial and access transactions should be initiated by the employee through known systems, not triggered by unexpected inbound calls, messages, or emails
- B.'Does the request come from a verified email domain with DMARC?'
- C.'Have I seen this person on video before and does the video look authentic?'
- D.'Is this request consistent with the requester's job title and level of authority?'
Why A is correct