Courseiva
Security Program Management and OversighthardMultiple SelectObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

After a phishing simulation, many employees still almost entered credentials into a fake login page. Leadership wants the fastest improvement without creating training fatigue or disrupting daily work. Which three measures are the best balance of security and usability? Select three.

⚠ Common exam trap

Candidates often confuse 'fastest improvement' with 'most aggressive technical control' (like option D) or 'public shaming' (like option E), failing to recognize that behavioral change through targeted, low-friction interventions (microtraining, reporting, and just-in-time prompts) yields faster and more sustainable results without alienating users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Provide targeted microtraining only to users who clicked or nearly clicked.

Targeted microtraining focuses only on the users who demonstrated risky behavior (clicking or nearly clicking), which directly addresses the root cause without wasting time on users who did not engage. This approach avoids training fatigue by keeping content brief and relevant, and it does not disrupt daily work for the majority of employees who already exhibit secure behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Provide targeted microtraining only to users who clicked or nearly clicked.

    Why this is correct

    Targeted microtraining is grounded in the principle that learning is most effective when immediately relevant to an individual's observed behavior. By focusing exclusively on employees who clicked or nearly clicked in the simulation, you provide specific, actionable feedback that addresses the actual risk without wasting the time of users who already demonstrated secure decision-making. This proportionate response also respects employee attention and maintains a collaborative security culture, while directly reinforcing the correct behavior for those who need it most.

  • Add a one-click report-phish button and acknowledge employee reports quickly.

    Why this is correct

    A one-click report-phish button removes the primary friction point in the reporting process, letting users redirect suspicious emails to the security team with a single action. Acknowledging reports quickly closes the feedback loop, teaching users that their vigilance has measurable value and encouraging repeated reporting. This approach transforms users into active sensors in the defense-in-depth strategy, improving detection while keeping daily workflow interference minimal.

  • Use just-in-time warning banners or link-check prompts when users follow external login pages.

    Why this is correct

    Just-in-time warning banners and link-check prompts are a form of nudge that presents a virtual 'speed bump' exactly when a user is about to enter credentials on an untrusted page. This contextual intervention draws on the moment of highest risk, when the user is most receptive to a warning, and can successfully interrupt an automated phishing response. Unlike generic annual training, this real-time feedback is scientifically shown to reduce click-through rates and credential compromise, making it a powerful, low-disruption supplement to user awareness.

  • Replace email access with a weekly manual approval queue for all messages.

    Why it's wrong here

    Implementing a weekly manual approval queue for every email would create an unacceptable operational bottleneck, delaying legitimate business communications and severely reducing productivity. Such a measure is a blunt-force, non-scalable control that does not teach any user to identify phishing; it merely shifts the burden to an approval team, which would quickly become a single point of failure. It is completely disproportionate to the risk identified by a phishing simulation, rather than an awareness-and-training improvement.

  • Publicly identify the worst performers in team meetings to discourage mistakes.

    Why it's wrong here

    Publicly shaming employees who fell for a phishing simulation fosters a blame-oriented security culture in which users conceal their errors instead of reporting them, significantly degrading the organization's threat visibility. Trust in the security team erodes, and the fear of embarrassment outweighs the intrinsic motivation to practice safe behavior, leading to reduced reporting quality and an increased likelihood of missed incidents. This approach directly contradicts best practices for security awareness, which emphasize constructive feedback and psychological safety.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.