After three months of phishing awareness training, the security team wants a metric that best shows whether employees are becoming harder to trick. Which metric is MOST useful?
Reporting rate is a strong indicator of awareness and response behavior because it measures whether employees recognize and escalate suspicious emails instead of interacting with them. A higher reporting rate generally shows improved vigilance and faster detection, which is more valuable than simply counting how many simulated messages were delivered.
Why this answer
The percentage of users who report suspicious messages before clicking links directly measures the effectiveness of phishing awareness training in changing user behavior. A higher reporting rate indicates that employees are recognizing phishing indicators and using the reporting mechanism (e.g., an integrated phishing report button or email forwarding to a security mailbox) instead of falling for the trick. This metric focuses on the desired outcome—reducing successful phishing—rather than activity volume.
Exam trap
CompTIA often tests the distinction between activity metrics (e.g., number of emails sent) and outcome metrics (e.g., reporting rate), and the trap here is assuming that more training or more simulations automatically means better security, when the real measure is behavioral change.
How to eliminate wrong answers
Option A is wrong because the total number of phishing simulation emails sent is a measure of campaign scale, not employee susceptibility; sending more simulations does not indicate whether users are harder to trick. Option C is wrong because the number of new usernames created in the email system is unrelated to phishing awareness; it reflects account provisioning or turnover, not security behavior. Option D is wrong because average screen resolution has no bearing on phishing detection; it is a display setting with no connection to email security or user vigilance.