Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

After a phishing campaign, 18 employees entered credentials on a fake login page. Management wants a program that both reduces future click rates and provides measurable improvement over time. What should security implement?

⚠ Common exam trap

Watch out — candidates often choose a technical control (like password complexity or email banners) thinking it addresses phishing, but the question specifically asks for a program that reduces click rates and provides measurable improvement—which requires a behavioral, training-based approach with metrics, not a static technical fix.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Simulated phishing with targeted follow-up training and metrics

Simulated phishing campaigns directly address the human factor by providing a controlled, repeatable test that measures click rates over time. When an employee falls for the simulation, targeted follow-up training (e.g., micro-learning modules) reinforces secure behavior, and the metrics (e.g., click-through rate, reporting rate) allow management to track improvement. This aligns with the security program management goal of continuous improvement through measurable security awareness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A one-time company email reminding employees to be careful

    Why it's wrong here

    A one-time company email is an ephemeral, passive awareness measure. It provides no mechanism to verify whether employees actually read, understood, and retained the guidance, nor does it offer any opportunity for hands-on practice. Because phishing threats evolve constantly, a single mailing lacks the reinforcement and metric collection needed to measure long-term behavioral change, and employees may dismiss it as just another generic security notice.

  • Simulated phishing with targeted follow-up training and metrics

    Why this is correct

    A simulated phishing program uses realistic, safe phishing tests that measure employees' real-world click and reporting behavior. Failing users are automatically enrolled in targeted, just-in-time follow-up training that explains the specific cues they missed, turning an error into a learning moment. Over time, the program produces quantitative metrics—click rates, reporting rates, and repeat offenders—that allow the security team to track improvement and adjust training. This aligns with security awareness best practices and specifically addresses the human factor that allowed 18 employees to enter credentials.

  • An updated password complexity rule for all users

    Why it's wrong here

    Enforcing a password complexity rule strengthens authentication but does nothing to help an employee recognize a fraudulent webpage before typing credentials. The incident already involved credentials being entered on a malicious site—complexity only raises the cost of cracking, not the likelihood of a phish being successful. In fact, overly complex rules can drive password reuse or storage in unsafe places, and they offer no feedback loop or measurement of phishing susceptibility. Multi-factor authentication and security awareness training would be more relevant defensive improvements.

  • A banner that all external email is untrusted

    Why it's wrong here

    An external email banner adds a visual warning to inbound messages from outside the organization, which may reduce impulsive clicking in the short term. However, it works as a universal filter rather than a teaching tool, so employees never learn to recognize the underlying social-engineering cues such as urgency, domain spoofing, or sender verifiability. Over time, banner fatigue sets in and users click through without reading, and the organization captures no per-user metrics that could drive coaching or measure improvement. It lacks the iterative, data-driven feedback that makes training effective.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.