SSCP Security Operations and Administration Practice Question
A security administrator is implementing a security awareness training program. The administrator wants to measure the effectiveness of the training in reducing phishing susceptibility. Which of the following metrics would be MOST indicative of the training's success?
⚠ Common exam trap
The trap here is equating training completion or technical blocks with behavioral change, when the real measure of effectiveness is how employees act when faced with a phishing attempt.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The number of phishing emails reported by employees during simulated campaigns.
To measure the effectiveness of phishing awareness training, the best metric is behavioral. The number of phishing emails reported during simulations shows whether employees are applying what they learned. Completion rate, gateway blocks, and training time do not directly measure reduced susceptibility. Therefore, reported phishing emails is the most indicative metric.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The total number of phishing emails blocked by the email gateway.
Why it's wrong here
The number of emails blocked by the gateway is a technical control metric, not a measure of employee behavior. It reflects the effectiveness of the email filtering system, not the training. Even with a good filter, some phishing emails will get through, so employee awareness is still critical. This metric does not indicate whether employees are less likely to fall for phishing.
- ✗
The average time taken by employees to complete the training module.
Why it's wrong here
The time taken to complete training does not correlate with effectiveness. An employee could rush through and retain little, or take their time and learn a lot. It is not a reliable indicator of phishing susceptibility. The focus should be on behavioral outcomes, such as reporting rates or click rates in simulations, rather than on training duration.
- ✓
The number of phishing emails reported by employees during simulated campaigns.
Why this is correct
The number of phishing emails reported by employees during simulations directly measures their ability to recognize and respond to phishing attempts. An increase in reporting indicates improved awareness and vigilance. This metric reflects behavioral change, which is the ultimate goal of security awareness training. It is a strong indicator of the training's effectiveness in reducing susceptibility.
- ✗
The percentage of employees who completed the training module.
Why it's wrong here
Completion rate measures participation, not effectiveness. Employees may complete the training without retaining the information or changing their behavior. While high completion is desirable, it does not indicate whether employees can recognize and avoid phishing attacks. The goal is to reduce susceptibility, so a behavioral metric is needed, not just a completion metric.
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.