Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

After several employees clicked on a realistic phishing email, management wants a control that both improves user behavior and gives the security team a way to measure improvement over time. Which approach is best?

⚠ Common exam trap

CompTIA often tests the distinction between administrative controls (like policies or reminders) and technical controls that provide both behavioral change and measurable outcomes, leading candidates to choose a simple policy reminder (Option A) instead of a proactive, data-driven approach like simulated phishing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Run simulated phishing campaigns with immediate feedback and follow-up training

Simulated phishing campaigns with immediate feedback and follow-up training directly address user behavior by providing a safe, controlled environment where employees can learn to recognize phishing attempts. This approach also gives the security team measurable metrics (e.g., click rates over time) to track improvement, aligning with the goal of both behavioral change and quantifiable assessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Send a company-wide reminder not to open suspicious emails

    Why it's wrong here

    A company-wide reminder is passive and generic; it merely asks employees to be cautious without giving them a safe way to practice identifying phishing cues. No interactive simulation or feedback loop exists, so there is no way to measure whether the reminder changed behavior or which employees remain vulnerable. Research in security education shows one-way communication rarely creates lasting behavioral change, and the reminder will likely be ignored or quickly forgotten in daily workflow.

  • Run simulated phishing campaigns with immediate feedback and follow-up training

    Why this is correct

    Simulated phishing campaigns are effective because they deliver a realistic, safe exercise that directly addresses the human factor in phishing. When an employee clicks a simulated link, immediate feedback appears at the moment of the mistake, allowing them to see what they missed, and follow-up training reinforces the correct recognition and reporting behavior. Each campaign round provides quantitative metrics (click rates, report rates) that let security teams track improvement over time and identify high-risk individuals for targeted coaching, making the intervention measurable and adaptive rather than a one-time broadcast.

  • Block all external email messages at the gateway

    Why it's wrong here

    Blocking all external email at the gateway is an extreme technical control that disrupts legitimate business communication and is rarely feasible or cost-effective. It does not educate employees or improve their ability to recognize phishing; instead, it treats a behavioral vulnerability as a pure technical barrier, which users may circumvent through personal email or other channels, creating shadow IT. Even if fully enforced, it fails to address the root cause—human susceptibility to social engineering—and leaves the organization vulnerable when users access external email outside the protected gateway.

  • Require employees to change passwords every week

    Why it's wrong here

    Requiring weekly password changes does not address phishing because phishing attacks aim to steal credentials or install malware, not simply exploit weak passwords. Frequent forced changes lead to password fatigue, prompting users to create simpler, predictable passwords or reuse them across sites, which can actually weaken security. Modern guidance, including NIST SP 800-63B, advises against arbitrary periodic rotation because it does not mitigate credential phishing, which intercepts the password at the point of entry regardless of how often it is changed.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.