SY0-701 Security Program Management and Oversight Practice Question
A security team wants to reduce repeated user mistakes after a phishing campaign without overwhelming employees with long training sessions. Which approach is best?
⚠ Common exam trap
Candidates often choose option B (full-day class) because they overestimate the value of comprehensive training, failing to recognize that targeted, immediate reinforcement is more effective for correcting specific, repeated mistakes without causing training fatigue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Send a short, targeted reminder to the affected users with a clear reporting path
It applies targeted, immediate reinforcement to the specific users who made mistakes, using a short reminder that clarifies the reporting path. This approach leverages just-in-time training, which has been shown to improve retention and behavior change without overwhelming employees. It directly addresses the root cause—repeated user errors—by providing a clear, actionable step (e.g., 'Report suspicious emails using the PhishAlarm button') rather than generic awareness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Send a short, targeted reminder to the affected users with a clear reporting path
Why this is correct
This is a focused security awareness intervention that addresses the specific repeated mistake without disrupting productivity. It leverages just-in-time training, reminding users of the correct reporting procedure (e.g., phishing reporting button) at the moment of risk. It also establishes a clear feedback loop so users know how to report future incidents. Unlike blanket training, it targets only affected users, reducing training fatigue and improving compliance.
- ✗
Require every employee to attend a full-day security class immediately
Why it's wrong here
A full-day class is heavy-handed for a localized behavioral issue; it imposes a significant operational cost on the entire organization. It also lacks immediacy and may be perceived as punitive, which can breed resentment and reduce engagement. Security awareness training is most effective when it is concise, frequent, and relevant; a one-time marathon session is less effective than ongoing micro-trainings. Moreover, it dilutes the specific lesson amidst broad content, failing to address the particular repeated mistake.
- ✗
Wait until the next annual training cycle and do nothing now
Why it's wrong here
This passive approach leaves the same risky behavior unmitigated for months, during which the organization remains exposed to phishing or other user-induced incidents. Annual training is too infrequent to correct a specific, recurring mistake; by the time it occurs, the behavior may have become entrenched. Modern security awareness relies on continuous reinforcement and timely feedback, not just annual compliance modules. Delaying action also ignores the chance to collect immediate telemetry about the failure and adjust controls or policies.
- ✗
Disable email access for all employees until they pass a new test
Why it's wrong here
This is an extreme and disproportionate response that would halt business operations and break legitimate workflows, including the very users who had no part in the mistake. It also creates an emergency support burden and may force employees to find shadow IT workarounds, increasing risk rather than reducing it. A technical control like conditional access or a targeted filter could reduce exposure without blocking all email. This approach violates the principle of least disruption and does not teach users the desired behavior; it only punishes everyone for a subset's error.
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.