Question 210 of 1,013
SY0-701 Security Program Management and Oversight Practice Question
Exhibit
Phishing simulation results for Q1: Finance: 22% clicked HR: 19% clicked Executive assistants: 28% clicked Users who reported the message using the reporting button: 41% Management goal: Reduce click rates and increase reporting over the next quarter.
Based on the exhibit, what should management implement next?
⚠ Common exam trap
CompTIA often tests the misconception that technical controls alone (like disabling attachments or changing passwords) can solve human-centric security issues, when in fact user training and awareness are the primary mitigations for phishing risks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role-based security awareness training with recurring phishing simulations and reporting practice.
The exhibit shows a user who clicked a phishing link and entered credentials, indicating a need for improved security awareness. Role-based training with phishing simulations directly addresses this human risk by teaching users to recognize and report such attacks, which is the most effective next step. This aligns with the Security Program Management domain's focus on continuous improvement through user education and testing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Role-based security awareness training with recurring phishing simulations and reporting practice.
Why this is correct
This is the best choice because the exhibit shows both low reporting and ongoing click rates across several groups. Role-based training helps target the people most affected, and repeated simulations measure whether behavior improves over time. Training should reinforce how to spot suspicious messages and how to report them correctly, which directly supports the management goal.
- ✗
Disable all email attachments for every user in the company.
Why it's wrong here
Disabling all email attachments is an extreme technical control that would cripple normal business workflows, since attachments are essential for sharing documents and files. Phishing attacks can also deliver payloads via links, embedded scripts, or external file-sharing URLs, so removing attachments does not address the full attack surface. Furthermore, this measure provides no education or feedback loop, leaving users just as vulnerable to other phishing lures and no better at reporting suspicious messages.
- ✗
Replace all passwords with longer usernames.
Why it's wrong here
Usernames are identity identifiers, not authentication secrets, so lengthening them does nothing to prevent credential theft through phishing or improve detection of malicious messages. A longer username might even be easier for an attacker to guess if it mirrors a user's full name or email address. The exhibit's data points to behavioral deficiencies—low reporting and repeated clicking—which require awareness training, not changes to account naming conventions.
- ✗
Move all users to a single shared mailbox for easier monitoring.
Why it's wrong here
Centralizing all users into a shared mailbox undermines individual accountability, making it impossible to track who clicks on phishing links or fails to report incidents, which is essential for targeted remediation. It also creates a single high-value target: one compromised shared mailbox exposes all users' aggregated data, increasing the impact of any successful attack. Finally, this approach does not teach users how to recognize phishing indicators; it encourages reliance on monitoring rather than building the vigilance the exhibit shows is lacking.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 30, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.