Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A security manager at a financial services company is evaluating the effectiveness of a newly deployed security awareness training program. The program included modules on recognizing phishing emails, password security, and tailgating. One month after the training, the manager wants to assess whether employees are applying the learned behaviors to reduce the risk of phishing attacks. Which of the following metrics would provide the most valid indication of the training's behavioral impact?

⚠ Common exam trap

A common mix-up: candidates confuse knowledge assessment (quiz scores) or participation metrics (completion rates) with behavioral metrics, but the exam specifically tests the distinction between measuring 'knowing' versus 'doing' in security awareness programs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The reduction in the employee click-through rate on simulated phishing campaigns.

The reduction in the employee click-through rate on simulated phishing campaigns directly measures a change in behavior—specifically, whether employees are applying the training to avoid clicking malicious links. Unlike knowledge scores or completion rates, this metric captures real-world application of the learned behavior in a controlled, measurable environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The percentage of employees who completed the training modules.

    Why it's wrong here

    The percentage of employees who completed the training modules only verifies that the learning content was accessed, not that it was understood, retained, or applied. Employees may click through the training while multitasking or simply to satisfy compliance, and completion rates ignore whether the material changed their decisions under real-world conditions. This metric measures training delivery, not training outcome, so it cannot distinguish a workforce that is fully engaged from one that merely satisfied a checkbox requirement.

    When this WOULD be correct

    A question asking for a metric to ensure training delivery compliance, such as 'Which metric best indicates that all employees have received the required security awareness training?'

  • The average score on the post-training knowledge quiz.

    Why it's wrong here

    Post-training knowledge quiz scores measure episodic recall of facts immediately after instruction, but they do not assess whether employees will respond correctly to a cleverly crafted phishing email weeks later. Quizzes often use recognition-based questions, which are easier than the generation and judgment required when a suspicious message appears in an inbox, and they are susceptible to memorization rather than genuine comprehension. A high score does not predict real-world behavior, whereas simulated phishing directly tests the behavior under pressure.

    When this WOULD be correct

    This option would be correct if the question asked: 'Which metric best indicates that employees understood the training content?' or 'Which metric should be used to evaluate the immediate knowledge retention from the training program?'

  • The number of reported phishing incidents to the security team.

    Why it's wrong here

    The number of reported incidents can be influenced by many factors, such as the volume of actual phishing attacks, reporting culture, and employee vigilance. It does not directly measure behavior change related to the training.

    When this WOULD be correct

    This metric would be correct if the question asked: 'Which metric best indicates employees are actively reporting suspicious emails after security awareness training?' In that context, an increase in reported incidents demonstrates application of reporting behavior.

  • The reduction in the employee click-through rate on simulated phishing campaigns.

    Why this is correct

    Simulated phishing campaigns provide a controlled, realistic threat environment that measures employees' actual clicking behavior rather than their theoretical knowledge. Comparing pre-training baseline click-through rates to post-training rates isolates the training's behavioral impact, directly showing whether employees now recognize and avoid phishing lures. This metric is the gold standard for security awareness effectiveness because it captures the exact risky behavior the training aims to reduce.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

The reduction in the employee click-through rate on simulated phishing campaigns.Correct answer

Why this is correct

Simulated phishing campaigns provide a controlled, realistic threat environment that measures employees' actual clicking behavior rather than their theoretical knowledge. Comparing pre-training baseline click-through rates to post-training rates isolates the training's behavioral impact, directly showing whether employees now recognize and avoid phishing lures. This metric is the gold standard for security awareness effectiveness because it captures the exact risky behavior the training aims to reduce.

The percentage of employees who completed the training modules.Wrong answer — click to see why

Why this is wrong here

Completion percentage measures participation, not behavioral change. The manager wants to assess whether employees are applying learned behaviors to reduce phishing risk, not just that they took the training.

★ When this WOULD be the correct answer

A question asking for a metric to ensure training delivery compliance, such as 'Which metric best indicates that all employees have received the required security awareness training?'

Why candidates choose this

Candidates may confuse training completion with training effectiveness, assuming that if everyone completed the training, it must have been effective.

The average score on the post-training knowledge quiz.Wrong answer — click to see why

Why this is wrong here

The average score on the post-training knowledge quiz measures theoretical understanding, not actual behavioral change. The question specifically asks for evidence that employees are applying learned behaviors to reduce phishing risk, which requires a behavioral metric like click-through rate reduction.

★ When this WOULD be the correct answer

This option would be correct if the question asked: 'Which metric best indicates that employees understood the training content?' or 'Which metric should be used to evaluate the immediate knowledge retention from the training program?'

Why candidates choose this

Candidates may assume that a high quiz score directly translates to real-world behavior, overlooking the gap between knowledge and action. They might also think that post-training assessment is the standard way to measure training effectiveness.

The number of reported phishing incidents to the security team.Wrong answer — click to see why

Why this is wrong here

The number of reported phishing incidents does not directly measure behavioral change; it may increase due to better reporting rather than reduced susceptibility. The question asks for the impact on reducing phishing risk, which is best measured by click-through rates on simulated phishing campaigns.

★ When this WOULD be the correct answer

This metric would be correct if the question asked: 'Which metric best indicates employees are actively reporting suspicious emails after security awareness training?' In that context, an increase in reported incidents demonstrates application of reporting behavior.

Why candidates choose this

Candidates may think that more reported incidents indicate greater security awareness, overlooking that reporting is a separate behavior from avoiding phishing clicks, and that increased reporting can occur even if click rates remain high.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.