Courseiva
Question 210 of 1,013
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Exhibit

Phishing simulation results for Q1:
Finance: 22% clicked
HR: 19% clicked
Executive assistants: 28% clicked
Users who reported the message using the reporting button: 41%

Management goal: Reduce click rates and increase reporting over the next quarter.

Based on the exhibit, what should management implement next?

⚠ Common exam trap

CompTIA often tests the misconception that technical controls alone (like disabling attachments or changing passwords) can solve human-centric security issues, when in fact user training and awareness are the primary mitigations for phishing risks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Role-based security awareness training with recurring phishing simulations and reporting practice.

The exhibit shows a user who clicked a phishing link and entered credentials, indicating a need for improved security awareness. Role-based training with phishing simulations directly addresses this human risk by teaching users to recognize and report such attacks, which is the most effective next step. This aligns with the Security Program Management domain's focus on continuous improvement through user education and testing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Role-based security awareness training with recurring phishing simulations and reporting practice.

    Why this is correct

    This is the best choice because the exhibit shows both low reporting and ongoing click rates across several groups. Role-based training helps target the people most affected, and repeated simulations measure whether behavior improves over time. Training should reinforce how to spot suspicious messages and how to report them correctly, which directly supports the management goal.

  • Disable all email attachments for every user in the company.

    Why it's wrong here

    Disabling all email attachments is an extreme technical control that would cripple normal business workflows, since attachments are essential for sharing documents and files. Phishing attacks can also deliver payloads via links, embedded scripts, or external file-sharing URLs, so removing attachments does not address the full attack surface. Furthermore, this measure provides no education or feedback loop, leaving users just as vulnerable to other phishing lures and no better at reporting suspicious messages.

  • Replace all passwords with longer usernames.

    Why it's wrong here

    Usernames are identity identifiers, not authentication secrets, so lengthening them does nothing to prevent credential theft through phishing or improve detection of malicious messages. A longer username might even be easier for an attacker to guess if it mirrors a user's full name or email address. The exhibit's data points to behavioral deficiencies—low reporting and repeated clicking—which require awareness training, not changes to account naming conventions.

  • Move all users to a single shared mailbox for easier monitoring.

    Why it's wrong here

    Centralizing all users into a shared mailbox undermines individual accountability, making it impossible to track who clicks on phishing links or fails to report incidents, which is essential for targeted remediation. It also creates a single high-value target: one compromised shared mailbox exposes all users' aggregated data, increasing the impact of any successful attack. Finally, this approach does not teach users how to recognize phishing indicators; it encourages reliance on monitoring rather than building the vigilance the exhibit shows is lacking.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 30, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.