mediummultiple choiceObjective-mapped

A security manager at a financial services company is evaluating the effectiveness of a newly deployed security awareness training program. The program included modules on recognizing phishing emails, password security, and tailgating. One month after the training, the manager wants to assess whether employees are applying the learned behaviors to reduce the risk of phishing attacks. Which of the following metrics would provide the most valid indication of the training's behavioral impact?

Question 1mediummultiple choice
Full question →

A security manager at a financial services company is evaluating the effectiveness of a newly deployed security awareness training program. The program included modules on recognizing phishing emails, password security, and tailgating. One month after the training, the manager wants to assess whether employees are applying the learned behaviors to reduce the risk of phishing attacks. Which of the following metrics would provide the most valid indication of the training's behavioral impact?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

The percentage of employees who completed the training modules.

Completion rate measures only that employees took the training, not whether they retained or applied the knowledge. It does not assess behavioral change.

B

Distractor review

The average score on the post-training knowledge quiz.

Quiz scores measure theoretical knowledge immediately after training, but they do not indicate whether employees will apply that knowledge in real-world scenarios.

C

Distractor review

The number of reported phishing incidents to the security team.

The number of reported incidents can be influenced by many factors, such as the volume of actual phishing attacks, reporting culture, and employee vigilance. It does not directly measure behavior change related to the training.

D

Best answer

The reduction in the employee click-through rate on simulated phishing campaigns.

Simulated phishing campaigns provide a controlled test of employee behavior. Comparing pre-training and post-training click-through rates directly measures whether employees are applying the training to avoid clicking malicious links.

Common exam trap

Common exam trap: answer the scenario, not the keyword

Many certification questions include familiar terms but test a specific constraint. Read the exact wording before choosing an answer that is generally true but wrong for this case.

Technical deep dive

How to think about this question

This question should be treated as a scenario, not a definition check. Identify the problem, the constraint and the best action. Then compare each option against those facts.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.
  • Use explanations to understand the rule behind the answer.

TExam Day Tips

  • Underline the problem statement mentally.
  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Related practice questions

Related SY0-701 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this SY0-701 question test?

Read the scenario before looking for a memorised answer.

What is the correct answer to this question?

The correct answer is: The reduction in the employee click-through rate on simulated phishing campaigns. — The most reliable indicator of training effectiveness is a measurable change in behavior. Simulated phishing campaigns allow the organization to collect baseline click rates before training and compare them with click rates after training. A reduction in clicks demonstrates that employees are applying the training in practice. Completion rates and quiz scores do not guarantee application, and reported phishing incidents are influenced by factors other than individual behavior.

What should I do if I get this SY0-701 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.