Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

After several employees clicked on phishing emails, management wants to reduce future click rates and show measurable improvement across finance, HR, and executive assistants. Which control best meets that goal?

⚠ Common exam trap

A common mix-up: candidates choose Option A or D because they equate 'training' with a one-time communication or annual sign-off, failing to recognize that measurable improvement requires simulation, role-specific content, and ongoing metrics tracking as specified in the CompTIA SY0-701 objectives for security awareness programs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use role-based security awareness training with phishing simulations and metrics tracking.

Role-based security awareness training with phishing simulations and metrics tracking directly addresses the human factor by tailoring content to specific job roles (finance, HR, executive assistants) and provides measurable improvement through simulation click-rate data. This approach aligns with the NIST SP 800-50 framework for continuous security awareness, enabling management to track reduction in click rates over time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Send a one-time company-wide memo reminding users not to click suspicious links.

    Why it's wrong here

    A one-time memo is a static, broadcast communication that lacks interactive reinforcement and behavioral measurement. Phishing resistance decays quickly without periodic, scenario-based practice, and users receive no feedback on their specific decisions. It also fails to differentiate risk by role or to track metrics such as click-through or incident report rates, so the organization cannot measure whether the intervention actually changed behavior. In contrast, ongoing simulations and targeted training create a feedback loop that builds detection skills and identifies at-risk users.

  • Use role-based security awareness training with phishing simulations and metrics tracking.

    Why this is correct

    Role-based awareness training with phishing simulations is the best fit because it directly targets user behavior and lets the security team measure results. Different job roles face different lures, so tailoring content to finance, HR, and executive assistants improves relevance. Tracking click rates, report rates, and repeat offenders also shows whether the program is working and supports continuous improvement.

  • Disable all external email attachments for every department indefinitely.

    Why it's wrong here

    This is an overly broad administrative control that disrupts legitimate business workflows by blocking all attachments from external senders, regardless of content, sender reputation, or user role. It also creates a false sense of security because phishing can arrive through links, embedded text, or compromised internal accounts, and users never learn to evaluate email context. Moreover, it ignores compensating controls like sandboxing or gateway filtering, and it does not address the human factor that training would strengthen. The operational impact and potential for users to create workarounds (e.g., personal email, file-sharing services) can be worse than the original risk.

  • Require employees to complete annual policy acknowledgment without testing.

    Why it's wrong here

    Annual policy acknowledgment verifies only that employees have read or acknowledged the policy, not that they can apply it under realistic phishing conditions. Because there is no simulation or assessment, it provides no measurement of detection skill, click propensity, or improvement over time. Also, once a year is too infrequent to counter current phishing tactics, which evolve rapidly, and the exercise is typically passive, with no customized follow-up for high-risk roles or repeat offenders. Without testing, the organization cannot identify gaps in user judgment or the effectiveness of the training program.

Go deeper

Related to this question

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. After a phishing simulation, many users still nearly entered credentials. Leadership wants to reduce repeat mistakes without causing long training sessions. Which two actions are the best balance of security and usability? Select two.

easy
  • A.Send a short targeted refresher focused on the exact mistake
  • B.Add an easy reporting button inside the email client
  • C.Require every employee to attend a full-day annual course this week
  • D.Publicly post the names of employees who clicked the simulation
  • E.Disable all email attachments for every user

Why A: A short, targeted refresher directly addresses the specific mistake (e.g., entering credentials on a phishing page) without overwhelming users. This approach leverages microlearning principles, which improve retention and reduce cognitive load compared to lengthy training. It balances security by reinforcing the exact behavior to avoid, while maintaining usability by minimizing time away from work. Additionally, adding an easy reporting button inside the email client empowers users to quickly flag suspicious messages, enabling faster response and reinforcing a security-conscious culture without requiring significant training time. Together, these actions provide immediate, low-friction security improvements while preserving productivity.

Variation 2. After a phishing simulation, many users still nearly entered credentials on the fake page. Security wants the fastest improvement without scheduling long training sessions. What is the best response?

easy
  • A.Require a full-day classroom course for every employee immediately.
  • B.Ignore the results because no actual breach occurred.
  • C.Send a short targeted awareness message with examples, warning signs, and reporting steps.
  • D.Reset every employee password as the main way to prevent future clicks.

Why C: A short targeted awareness message directly addresses the observed risky behavior with minimal time investment, providing immediate reinforcement of warning signs and reporting procedures. This approach leverages just-in-time training, which is proven to improve retention and behavior change more effectively than lengthy sessions, aligning with the goal of fastest improvement without disrupting operations.

Variation 3. A security team wants to reduce repeated user mistakes after a phishing campaign without overwhelming employees with long training sessions. Which approach is best?

easy
  • A.Send a short, targeted reminder to the affected users with a clear reporting path
  • B.Require every employee to attend a full-day security class immediately
  • C.Wait until the next annual training cycle and do nothing now
  • D.Disable email access for all employees until they pass a new test

Why A: It applies targeted, immediate reinforcement to the specific users who made mistakes, using a short reminder that clarifies the reporting path. This approach leverages just-in-time training, which has been shown to improve retention and behavior change without overwhelming employees. It directly addresses the root cause—repeated user errors—by providing a clear, actionable step (e.g., 'Report suspicious emails using the PhishAlarm button') rather than generic awareness.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.