Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Several employees nearly entered credentials into a fake mailbox login page. The security team wants to reduce repeat mistakes quickly without overwhelming the whole company. What is the best communication approach?

⚠ Common exam trap

A common mix-up: candidates choose a company-wide message (Option D) thinking it will deter others, but the SY0-701 exam emphasizes privacy and targeted remediation over public shaming or broad disruption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Send a short targeted notice to the affected users with examples, warning signs, and reporting steps

A short targeted notice to the affected users is the best approach because it directly addresses the immediate threat without overwhelming the entire company. This method allows the security team to quickly reinforce specific warning signs (e.g., mismatched URLs, lack of HTTPS/TLS certificates) and reporting procedures, reducing the likelihood of repeat mistakes while maintaining operational efficiency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Send a short targeted notice to the affected users with examples, warning signs, and reporting steps

    Why this is correct

    Targeted, timely communication is the best way to improve behavior quickly. A concise alert with screenshots or warning signs helps users recognize the specific threat they encountered, and clear reporting steps make it easier to respond correctly next time. This approach is practical, low disruption, and focused on the people most likely to benefit from immediate coaching.

  • Wait until the annual security training cycle to address the issue

    Why it's wrong here

    Annual security training is a foundational control, but it fails to address an active phishing pattern in a timely manner. Because memory of the near-miss decays quickly, delaying feedback until the next annual cycle means employees no longer associate the warning signs with the concrete incident they just encountered. The window of heightened vigilance closes within days, so an annual refresher cannot interrupt the current attack campaign or prevent the same lure from succeeding tomorrow. Effective awareness requires just-in-time reinforcement, not a scheduled reminder months later.

  • Disable all external email until the next awareness campaign is completed

    Why it's wrong here

    This response creates a disproportionate operational impact: external email is a core business communication channel, and blocking it for all users halts workflows, customer interactions, and partner transactions. It also teaches nothing about threat recognition, leaving users untrained for the next lure once mail is restored, and it may drive users to circumvent the block through personal email, increasing risk. The incident involved a few users falling for a fake mailbox, not a systemic infrastructure compromise, so a global block is an overreaction that damages trust in the security team and does not address the root cause of weak phishing detection.

  • Send a company-wide message naming the affected employees to discourage mistakes

    Why it's wrong here

    Publicly naming the affected employees in a company-wide message is a punitive measure that violates their privacy and creates a culture of fear rather than learning. Employees who see peers shamed will be less likely to report future phishing attempts, which ironically increases the organization's exposure. This approach also ignores the core issue: the users lacked the ability to recognize a convincing fake mailbox, and embarrassment does not teach them the specific indicators (e.g., sender domain, URL preview, or unsolicited credential prompt). Security awareness should be corrective, supportive, and focused on behavior change, not on using individuals as a deterrent example.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.