Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A security manager is evaluating the effectiveness of a new security awareness training program that all employees completed last quarter. The company has been conducting monthly phishing simulation campaigns for the past year. Which of the following metrics would provide the strongest evidence that the training is achieving its intended goal of changing employee behavior?

⚠ Common exam trap

Test-takers frequently choose Option B (increased reporting) because it sounds proactive, but the question specifically asks for evidence of 'changing employee behavior' away from clicking, not just improving reporting habits.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The percentage of employees who clicked on a simulated phishing email decreased from 18% to 6%.

Directly measures the reduction in risky behavior (clicking phishing links) after training, which is the core goal of security awareness training. A drop from 18% to 6% demonstrates a measurable behavior change, not just knowledge acquisition. This aligns with the Kirkpatrick Model's 'Behavior' level of evaluation, which is the strongest indicator of training effectiveness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • 95% of employees completed the training within the deadline.

    Why it's wrong here

    Training completion rate measures whether employees were exposed to the material, not whether they learned, retained, or changed any security behavior. An employee can click through modules without absorbing the content, especially if completion is enforced by management or an LMS deadline. This is a process metric—it verifies that training was delivered and tracked, but it does not demonstrate that employees are now less likely to fall for phishing or follow secure procedures. Therefore, a 95% completion rate is necessary but wholly insufficient to prove training effectiveness.

    When this WOULD be correct

    A question asking for evidence of training program adoption or compliance, e.g., 'Which metric best indicates that employees completed the mandatory training on time?'

  • The number of employees reporting phishing attempts to the SOC increased by 40%.

    Why it's wrong here

    Increased reporting indicates better awareness, but it does not directly measure whether employees are less likely to click on phishing emails. It is possible that more reports are coming from a small group while the overall click rate remains unchanged.

    When this WOULD be correct

    This option would be correct if the question asked: 'Which metric best indicates that employees are more vigilant and actively participating in the security program?' or 'Which metric demonstrates an increase in security-conscious behavior following training?'

  • The percentage of employees who clicked on a simulated phishing email decreased from 18% to 6%.

    Why this is correct

    A simulated phishing click-through rate is a direct behavioral measure: it tests precisely the skill the training is designed to improve, and the marked drop from 18% to 6% shows employees are applying their knowledge in realistic conditions. Unlike self-reports or knowledge quizzes, this metric captures actual decision-making under a simulated attack, making it strong evidence of decreased susceptibility. The pre/post comparison controls for prior awareness and isolates the training’s impact on the target behavior, which is why it is the most convincing effectiveness indicator.

  • The number of helpdesk tickets related to password resets decreased by 10%.

    Why it's wrong here

    Password reset ticket volume is a poor evaluation metric because it is affected by many unrelated variables: password expiration schedules, adoption of self-service password resets, single sign-on configurations, and multifactor authentication lockouts can all reduce tickets without any change in security behavior. Even when security training includes password best practices, a drop in helpdesk tickets does not reveal whether users are phishing-aware, use stronger passwords, or recognize social engineering. This metric conflates operational efficiency, system changes, and user behavior, so it cannot isolate the training’s true effect.

    When this WOULD be correct

    This metric would be correct if the question asked for evidence that the training improved password hygiene or reduced account compromise incidents, such as after a training module on password security and multi-factor authentication.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

The percentage of employees who clicked on a simulated phishing email decreased from 18% to 6%.Correct answer

Why this is correct

A simulated phishing click-through rate is a direct behavioral measure: it tests precisely the skill the training is designed to improve, and the marked drop from 18% to 6% shows employees are applying their knowledge in realistic conditions. Unlike self-reports or knowledge quizzes, this metric captures actual decision-making under a simulated attack, making it strong evidence of decreased susceptibility. The pre/post comparison controls for prior awareness and isolates the training’s impact on the target behavior, which is why it is the most convincing effectiveness indicator.

95% of employees completed the training within the deadline.Wrong answer — click to see why

Why this is wrong here

Completion rate (95%) measures training participation, not behavior change. The goal is to reduce risky actions like clicking phishing links, not just completing modules.

★ When this WOULD be the correct answer

A question asking for evidence of training program adoption or compliance, e.g., 'Which metric best indicates that employees completed the mandatory training on time?'

Why candidates choose this

Candidates confuse completion rates with effectiveness, assuming high participation automatically means behavior change.

The number of employees reporting phishing attempts to the SOC increased by 40%.Wrong answer — click to see why

Why this is wrong here

An increase in reporting phishing attempts indicates improved awareness, but it does not directly measure behavior change in terms of reducing risky actions like clicking. The question specifically asks for evidence of behavior change, and reporting is a secondary action, not the primary risky behavior.

★ When this WOULD be the correct answer

This option would be correct if the question asked: 'Which metric best indicates that employees are more vigilant and actively participating in the security program?' or 'Which metric demonstrates an increase in security-conscious behavior following training?'

Why candidates choose this

Candidates may think that more reporting directly correlates with better security behavior, overlooking that the core goal is to reduce clicks, not just increase reports. They might also confuse awareness (knowing to report) with behavior change (not clicking).

The number of helpdesk tickets related to password resets decreased by 10%.Wrong answer — click to see why

Why this is wrong here

A decrease in password reset tickets is not directly tied to security awareness training; it could result from other factors like improved password policies or self-service tools, and does not measure behavioral change regarding phishing or security awareness.

★ When this WOULD be the correct answer

This metric would be correct if the question asked for evidence that the training improved password hygiene or reduced account compromise incidents, such as after a training module on password security and multi-factor authentication.

Why candidates choose this

Candidates may assume that any positive metric following training indicates effectiveness, overlooking that password resets are not a direct measure of security awareness behavior change.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.