A security awareness program includes phishing simulations. Which THREE factors should be considered when designing the simulation frequency and difficulty? (Select THREE)
Role and job function determine exposure to targeted attacks, such as finance staff facing invoice fraud or executives facing spear phishing. Tailoring simulation difficulty by function ensures relevance and avoids over-testing low-risk roles, satisfying the stem's design factor requirement.
Why this answer
Option B (Employee role and job function) is correct because employees in finance, HR, or executive roles face different phishing lures and risk levels, so simulations should be tailored to the specific threats and responsibilities of each role. Option C (Past phishing click rate trends) is correct because historical click-rate data reveals which users or departments are most susceptible, allowing frequency and difficulty to be adjusted upward or downward based on demonstrated performance. Option E (Current threat landscape and prevalent attack types) is correct because simulations must reflect real-world tactics such as credential harvesting, QR-code phishing, or business email compromise that are actively trending, ensuring training stays relevant.
Option A (Employee's years of service) is not a reliable indicator of phishing susceptibility, since tenure does not correlate consistently with security awareness or behavior. Option D (Number of security incidents in the past year) is too broad and lagging an indicator; it does not directly inform the design of phishing simulation frequency or difficulty the way role, click trends, and threat landscape do.