Based on the exhibit, which metric best indicates improved phishing resistance?
Phish report rate measures the proportion of simulated or real phishing deliveries that users report through the designated reporting mechanism. It directly reflects whether employees are not only recognizing suspicious messages but also taking the correct security action, making it a leading indicator of phishing resistance. Higher report rates typically correlate with lower engagement with malicious emails and better SOC visibility.
Why this answer
The phish report rate measures how many users report a simulated phishing email to the security team, which directly indicates their ability to recognize and respond to phishing attempts. A higher report rate demonstrates improved security awareness and resistance because users are actively identifying threats rather than ignoring or falling for them. This metric is a key performance indicator in security awareness programs because it reflects behavioral change, not just training completion.
Exam trap
CompTIA often tests the misconception that training completion rate (Option A) is the best indicator of security awareness, but the exam emphasizes that behavioral metrics like phish report rate are more meaningful because they measure actual user response to threats.
How to eliminate wrong answers
Option A is wrong because training completion rate only measures whether users finished the training module, not whether they retained or applied the knowledge to resist phishing attacks. Option B is wrong because the number of phishing emails sent by attackers is an external threat metric that the organization cannot control and does not reflect user resistance or program effectiveness. Option D is wrong because the total number of help desk tickets is a broad metric that includes many unrelated issues (e.g., password resets, software problems) and does not specifically measure phishing resistance or user reporting behavior.