SY0-701 Security Program Management and Oversight Practice Question
A security analyst is reviewing the organization’s security awareness program. Which three of the following are key metrics that demonstrate the effectiveness of the program? (Choose three.)
⚠ Common exam trap
It's easy for candidates to confuse operational security metrics (like patch time or encryption coverage) with human-centric awareness metrics, leading them to select technical controls that do not measure employee behavior or program effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Percentage of employees who complete annual security training
The percentage of employees who complete annual security training is a key metric because it measures participation in the foundational awareness activity. The number of phishing simulation clicks before and after training directly quantifies behavioral change, showing whether training reduces susceptibility to social engineering. The total count of security incidents reported by employees indicates whether the program has successfully fostered a culture of reporting, which is critical for early threat detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Percentage of employees who complete annual security training
Why this is correct
This is a direct coverage metric for the awareness program, indicating the percentage of employees who received and completed the mandatory baseline training. While completion does not guarantee retention or behavior change, it confirms that the required instruction was actually delivered to the workforce, making it a valid leading indicator of program reach.
- ✓
Number of phishing simulation clicks before and after training
Why this is correct
This metric measures a specific behavioral outcome: how often employees fall for simulated phishing emails. Comparing click rates before and after training directly assesses whether employees have learned to recognize and avoid a common social engineering vector, providing concrete evidence of training effectiveness and risk reduction.
- ✓
Total count of security incidents reported by employees
Why this is correct
This metric captures employees' active application of security knowledge by measuring how often they voluntarily report suspicious emails, attachments, or other potential incidents. A higher reporting count indicates that employees are engaged, observant, and willing to alert the security team, which reflects a positive security culture and effective awareness program.
- ✗
Average time to patch critical vulnerabilities in production systems
Why it's wrong here
This is a vulnerability management metric that reflects patching speed, risk prioritization, and IT operational efficiency, not the security knowledge or behavior of employees. While critical for reducing exposure, it depends on system administrators and automated processes rather than on the awareness curriculum, so it is not a valid measure of the training program's impact.
- ✗
Number of firewall rule changes approved per quarter
Why it's wrong here
This is a network administration and change management metric that counts firewall rule changes, which are typically driven by application requirements, business need, or security engineering work. It does not involve employee knowledge or decision-making, and it measures operational throughput rather than the effectiveness or reach of a security awareness program.
- ✗
Percentage of servers with full disk encryption enabled
Why it's wrong here
This is a data-at-rest protection metric that measures the percentage of servers configured with full disk encryption, a technical control enforced by IT policies and system settings. It is a configuration management and endpoint security measure, unrelated to employee awareness or training, and therefore does not evaluate the awareness program's success.
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.