Why is security awareness training important for all employees, not just IT staff?
- A.A. IT staff are the only ones who can be targeted
- B.D. Training is only required by regulation
- C.C. Non-technical employees don't have access to sensitive data
- D.B. Humans are often the weakest link in security - social engineering targets all employees regardless of technical role
Why D is correct
Social engineering attacks target all employees, from receptionists to executives. Even non-technical staff handle sensitive information, click email links, and have network access. Security awareness training helps everyone recognize phishing, follow security policies, and report suspicious activity. Regular training and simulated phishing reduce human-related breaches.
Know someone studying for Security Fundamentals? Send them this one.