Courseiva
Security Program Management and OversighteasyMultiple SelectObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

After a phishing campaign, several employees entered credentials on a fake login page. Management wants a control that both improves user behavior and gives the security team a way to measure whether click rates are going down. Which two actions best meet that goal? Select two.

⚠ Common exam trap

CompTIA often tests the distinction between passive awareness (like annual emails) and active, measurable training (like simulated phishing with metrics), leading candidates to mistakenly select a single control that only addresses one aspect of the goal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Run role-based phishing awareness training

Role-based phishing awareness training (B) directly improves user behavior by tailoring content to specific job functions, making the training more relevant and effective. Simulated phishing exercises with reporting metrics (D) provide a measurable way for the security team to track click rates over time, enabling data-driven assessment of improvement. Together, they address both behavioral change and quantifiable measurement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Send a reminder email once a year and stop there

    Why it's wrong here

    A single annual email relying on generic advice is a passive, one-time intervention that fails to condition employees to recognize current phishing lures. Threats evolve rapidly, but a yearly reminder offers no adaptive scenarios, no behavioral assessment, and no immediate reinforcement after an incident, so employees continue to operate with unsafe baseline habits.

  • Run role-based phishing awareness training

    Why this is correct

    Role-based phishing awareness training maps real-world scenarios to each employee's job function—finance teams practice spotting BEC invoices, HR recognizes W-2 scams, and developers identify credential-harvesting pages—so the lessons feel relevant and memorable. This approach reduces cognitive overload by focusing on the attack types most likely to target that role and allows training teams to track competence before and after the campaign.

  • Disable all external email for every employee

    Why it's wrong here

    Disabling external email is a blunt technical control that cripples normal business operations and still fails to mitigate phishing from compromised internal accounts, cloud-shared documents, or web-delivered credential harvesters. Email gateways should instead apply layered filtering, DMARC/DKIM/SPF validation, and sender reputation—while users remain the last line of defense, not a segment to be isolated.

  • Use simulated phishing exercises with reporting metrics

    Why this is correct

    Simulated phishing exercises with reporting metrics give the team measurable, empirical data on how many users clicked, how quickly they reported, and which departments remain vulnerable—turning awareness from theory into observed behavior. Repeating these simulations and feeding results into training reinforces learning, but the key is tracking the metric of user-reported suspicious content, which dramatically shortens response time and prevents real incidents from spreading across the organization.

  • Tell users to ignore suspicious messages unless IT calls first

    Why it's wrong here

    Instructing users to ignore suspicious messages unless IT calls first creates an unsafe reliance on after-the-fact notification and kills the very reporting behavior that catches real phish before it can propagate. Modern phishing campaigns often impersonate IT, so users must instead be trained to use the email client's 'Report Message' button or a security mailbox, enabling a rapid SOC response rather than waiting for a phone call that may never arrive.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.