SY0-701 Security Program Management and Oversight Practice Question
Exhibit
Phishing simulation results from the last 30 days: - Executives: 24% clicked, 0% reported - Customer Support: 19% clicked, 1% reported - Finance: 11% clicked, 3% reported - IT: 6% clicked, 8% reported Program note: - The organization wants to reduce user clicks and improve reporting of suspicious messages.
Based on the exhibit, which awareness action should the security manager prioritize next?
⚠ Common exam trap
A common mix-up: candidates choose Option A (annual slide deck) because they assume any awareness training is sufficient, but the exam emphasizes that targeted, risk-based training is more effective than generic, one-size-fits-all approaches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Launch role-based phishing training and reporting reinforcement for the highest-risk groups.
The exhibit shows that the highest-risk groups (e.g., finance, executives) have the highest phishing click rates. Option B is correct because role-based phishing training targets these specific users with simulated phishing campaigns and reporting reinforcement, which directly reduces the likelihood of successful social engineering attacks. This aligns with the principle of prioritizing remediation based on risk assessment data rather than blanket training.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send the same annual awareness slide deck to everyone again without changing the content.
Why it's wrong here
Sending the same annual awareness slide deck to everyone again without changing the content will not resolve the behavioral gaps highlighted in the exhibit. The data shows that executives and customer support have disproportionately high click rates and near-zero reporting rates, which generic, annual, static content fails to address. Repeated, unchanged material leads to habituation and offers no practice or reinforcement, so it is an ineffective awareness action.
- ✓
Launch role-based phishing training and reporting reinforcement for the highest-risk groups.
Why this is correct
The results show that executives and customer support need the most help, especially because reporting is near zero for executives. Targeted training and practice campaigns are more effective than one-size-fits-all messaging because they address the actual behavior patterns shown in the exhibit.
- ✗
Block all external email so users cannot click suspicious messages.
Why it's wrong here
Blocking all external email is an excessively restrictive technical control that would severely disrupt business operations and legitimate communication. Even if it were implemented, it would not address the underlying awareness deficit because attackers can pivot to other vectors like internal phishing, compromised accounts, or web-based lures, and it provides no training on how to identify or report suspicious messages. Security awareness requires enabling users to make good decisions, not isolating them from all external contact.
- ✗
Take no action because IT already reports suspicious messages well.
Why it's wrong here
Taking no action because IT already reports suspicious messages well is a dangerous assumption, as the exhibit shows that other departments, particularly executives and customer support, have very low report rates. The overall security posture depends on every employee, not just IT, because attacks target all users, and a single high-performing group does not mitigate the risk posed by groups with weak detection and reporting behavior. Ignoring the exhibit's evidence of poor performance in other groups leaves the organization vulnerable to phishing and business email compromise.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Risk assessment
Risk assessment is the process of identifying, analyzing, and evaluating potential threats to an organization's assets to determine the likelihood and impact of those threats, and to decide on appropriate treatment measures.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.