Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Several employees reported a text message that looked like it came from the VPN support team and linked to a fake sign-in page. Management wants to reduce future success of these attacks and improve how quickly users report suspicious messages. What should the security team implement?

⚠ Common exam trap

Many candidates choose Option C (disable text messaging) because it seems like a definitive technical control, but the question specifically asks to reduce future success and improve reporting speed, which requires user training and a streamlined reporting process, not a blanket ban that breaks business functionality.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Run role-based smishing simulations and provide a simple reporting workflow

Smishing simulations train users to recognize phishing SMS attacks in a controlled environment, directly reducing susceptibility. A simple reporting workflow (e.g., a dedicated email address or button in the messaging app) lowers the friction for users to report suspicious messages, enabling faster incident response. This combination addresses both the reduction of attack success and the improvement of reporting speed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Send one annual lecture to all staff and close the ticket

    Why it's wrong here

    A single annual lecture is a passive, one-time event that relies on cognitive retention rather than building an active detection habit. Smishing attacks constantly evolve, so training must be repeated and realistic to keep users vigilant and to measure whether they actually apply the knowledge. This approach also fails to provide data on user susceptibility or progress, making it impossible to gauge improvement or target follow-up training.

  • Run role-based smishing simulations and provide a simple reporting workflow

    Why this is correct

    Role-based smishing simulations tailor realistic phishing scenarios to the user's job function, such as a fake expense report for finance or a fraudulent wire-transfer request for executives, which makes the training relevant and memorable. Combining these with a simple reporting workflow—for example, a 'Report Phish' button in the email client or a shared SMS inbox—enables users to report suspicious texts quickly and helps the security team collect threat intelligence and respond faster. This combination changes user behavior, reinforces secure habits, and produces measurable metrics like click rate and report rate.

  • Disable text messaging for every employee mobile device

    Why it's wrong here

    Disabling text messaging on all employee mobile devices is an extreme measure that disrupts legitimate business communications and workflows, and it would likely be met with strong resistance. Even if technically feasible via MDM, it does not address the underlying vulnerability—the user's ability to recognize and resist social engineering—so users remain susceptible to smishing on personal phones or through other messaging apps. The risk is shifted, not eliminated, and this approach undermines productivity without providing any educational or measurable benefit.

  • Require managers to approve every external message before users open it

    Why it's wrong here

    Requiring managers to approve every external message is operationally unrealistic because the volume of external communication in a typical enterprise is enormous, causing severe delays and a bottleneck that would stall business processes. There is also no standard technical mechanism to intercept and hold SMS messages for a manager's manual review on all device types and carriers, and such a rule would not teach users anything about detecting threats. It creates a cumbersome approval chain that shifts security burden to managers rather than building security awareness across the workforce.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.