SY0-701 Security Program Management and Oversight Practice Question
After a phishing-awareness campaign, which metric best shows that employees are becoming more resistant to phishing attempts?
⚠ Common exam trap
Many exam-takers confuse security awareness metrics with technical controls (e.g., spam filtering or antivirus), but the question specifically asks for a metric showing employee behavioral change, not infrastructure effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The percentage of users who click phishing test links
The percentage of users who click phishing test links directly measures behavioral change in response to simulated phishing attacks. A decreasing click rate indicates that employees are better at recognizing and avoiding phishing attempts, which is the primary goal of a phishing-awareness campaign.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The number of spam emails received by the mail gateway
Why it's wrong here
Incoming spam volume is an infrastructure-level metric shaped by external threat actor campaigns, blacklist reputations, and gateway filtering rules, not by employee behavior. An effective phishing awareness campaign does not reduce spam volume, and a reduction in spam does not imply that users are better at recognizing socially engineered messages. Consequently, this metric has no direct causal relationship with the success of user training.
- ✗
The average length of employee passwords
Why it's wrong here
Average password length reflects an authentication security control that is enacted through password complexity policies and technical enforcement. Phishing attacks frequently collect credentials by tricking users into entering them on fraudulent websites, thereby bypassing the strength of the password itself. Thus, password length does not measure a user's ability to detect deception, nor does it correlate with susceptibility to phishing attempts, making it an irrelevant benchmark for awareness training.
- ✗
The count of antivirus alerts on endpoints
Why it's wrong here
The count of antivirus alerts indicates malware activity that may or may not stem from a phishing interaction; many phishing campaigns use credential-harvesting pages that never deliver a malicious file to the endpoint. Also, endpoint protection software, patch levels, and user reporting habits all influence alert counts independently of user awareness. As a result, antivirus alerts are a noisy downstream signal that cannot isolate whether employees recognized and avoided phishing messages.
- ✓
The percentage of users who click phishing test links
Why this is correct
The click-through rate on simulated phishing links directly measures the specific human behavior that awareness training aims to change: whether employees recognize and resist phishing lures. A declining click rate after training demonstrates improved resilience against social engineering and is a commonly accepted key performance indicator for security awareness. This metric is practical, repeatable, and directly attributable to the training program, unlike technical controls or infrastructure statistics.
Go deeper
Related to this question
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.