SY0-701 Security Program Management and Oversight Practice Question
After several employees clicked on a realistic phishing email, management wants a control that both improves user behavior and gives the security team a way to measure improvement over time. Which approach is best?
⚠ Common exam trap
CompTIA often tests the distinction between administrative controls (like policies or reminders) and technical controls that provide both behavioral change and measurable outcomes, leading candidates to choose a simple policy reminder (Option A) instead of a proactive, data-driven approach like simulated phishing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run simulated phishing campaigns with immediate feedback and follow-up training
Simulated phishing campaigns with immediate feedback and follow-up training directly address user behavior by providing a safe, controlled environment where employees can learn to recognize phishing attempts. This approach also gives the security team measurable metrics (e.g., click rates over time) to track improvement, aligning with the goal of both behavioral change and quantifiable assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send a company-wide reminder not to open suspicious emails
Why it's wrong here
A company-wide reminder is passive and generic; it merely asks employees to be cautious without giving them a safe way to practice identifying phishing cues. No interactive simulation or feedback loop exists, so there is no way to measure whether the reminder changed behavior or which employees remain vulnerable. Research in security education shows one-way communication rarely creates lasting behavioral change, and the reminder will likely be ignored or quickly forgotten in daily workflow.
- ✓
Run simulated phishing campaigns with immediate feedback and follow-up training
Why this is correct
Simulated phishing campaigns are effective because they deliver a realistic, safe exercise that directly addresses the human factor in phishing. When an employee clicks a simulated link, immediate feedback appears at the moment of the mistake, allowing them to see what they missed, and follow-up training reinforces the correct recognition and reporting behavior. Each campaign round provides quantitative metrics (click rates, report rates) that let security teams track improvement over time and identify high-risk individuals for targeted coaching, making the intervention measurable and adaptive rather than a one-time broadcast.
- ✗
Block all external email messages at the gateway
Why it's wrong here
Blocking all external email at the gateway is an extreme technical control that disrupts legitimate business communication and is rarely feasible or cost-effective. It does not educate employees or improve their ability to recognize phishing; instead, it treats a behavioral vulnerability as a pure technical barrier, which users may circumvent through personal email or other channels, creating shadow IT. Even if fully enforced, it fails to address the root cause—human susceptibility to social engineering—and leaves the organization vulnerable when users access external email outside the protected gateway.
- ✗
Require employees to change passwords every week
Why it's wrong here
Requiring weekly password changes does not address phishing because phishing attacks aim to steal credentials or install malware, not simply exploit weak passwords. Frequent forced changes lead to password fatigue, prompting users to create simpler, predictable passwords or reuse them across sites, which can actually weaken security. Modern guidance, including NIST SP 800-63B, advises against arbitrary periodic rotation because it does not mitigate credential phishing, which intercepts the password at the point of entry regardless of how often it is changed.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.