Courseiva

SSCP Security Operations and Administration Practice Question

A security awareness training program aims to reduce successful phishing attacks. Which metric is most appropriate for measuring the effectiveness of this training?

⚠ Common exam trap

Watch out — candidates often confuse activity metrics (like completion rate) with outcome metrics (like click rate). Candidates often pick completion rate because it's easy to measure, but the exam expects you to choose the metric that directly reflects the training's goal: reducing successful phishing attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Percentage of employees who click simulated phishing links

The percentage of employees who click simulated phishing links is the most appropriate metric because it directly measures the behavior the training aims to change—whether employees can recognize and avoid phishing attempts. A decrease in click rate over time indicates improved awareness and reduced susceptibility. This is a direct, outcome-based measure of training effectiveness, unlike completion rates which only show participation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Percentage of employees who click simulated phishing links

    Why this is correct

    Click rate on simulated phishing links directly measures whether employees apply the training, since clicking is the behaviour the programme targets. It satisfies the stem's effectiveness requirement by quantifying real susceptibility rather than completion or awareness, which do not prove reduced phishing success.

  • ✗

    Training completion rate

    Why it's wrong here

    Training completion rate records attendance, not whether behaviour changed, so it cannot show reduced phishing susceptibility. It is tempting because completion tracking suits compliance reporting and audit evidence, where demonstrating that staff finished assigned modules is the actual requirement. Measuring effectiveness instead demands a metric tied to phishing outcomes, such as click or report rates.

  • ✗

    Number of reported phishing emails

    Why it's wrong here

    Reported phishing emails measure user engagement with reporting, not whether attacks succeed; a rise can even accompany improved detection. It tempts because reporting volume suits evaluating a reporting button or mailbox rollout. Effectiveness at reducing successful phishing requires the click and credential-submission rate, or the resulting compromise count.

  • ✗

    Number of security incidents caused by phishing

    Why it's wrong here

    Phishing incident counts reflect real-world outcomes but are confounded by attack volume, reporting rates and detection coverage, so they cannot isolate training's effect. It is tempting because incident reduction is the program's ultimate goal; this metric suits measuring overall security posture, not the training intervention itself.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.