SSCP Security Operations and Administration Practice Question
A security awareness training program aims to reduce successful phishing attacks. Which metric is most appropriate for measuring the effectiveness of this training?
⚠ Common exam trap
Watch out — candidates often confuse activity metrics (like completion rate) with outcome metrics (like click rate). Candidates often pick completion rate because it's easy to measure, but the exam expects you to choose the metric that directly reflects the training's goal: reducing successful phishing attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Percentage of employees who click simulated phishing links
The percentage of employees who click simulated phishing links is the most appropriate metric because it directly measures the behavior the training aims to change—whether employees can recognize and avoid phishing attempts. A decrease in click rate over time indicates improved awareness and reduced susceptibility. This is a direct, outcome-based measure of training effectiveness, unlike completion rates which only show participation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Percentage of employees who click simulated phishing links
Why this is correct
Click rate on simulated phishing links directly measures whether employees apply the training, since clicking is the behaviour the programme targets. It satisfies the stem's effectiveness requirement by quantifying real susceptibility rather than completion or awareness, which do not prove reduced phishing success.
- ✗
Training completion rate
Why it's wrong here
Training completion rate records attendance, not whether behaviour changed, so it cannot show reduced phishing susceptibility. It is tempting because completion tracking suits compliance reporting and audit evidence, where demonstrating that staff finished assigned modules is the actual requirement. Measuring effectiveness instead demands a metric tied to phishing outcomes, such as click or report rates.
- ✗
Number of reported phishing emails
Why it's wrong here
Reported phishing emails measure user engagement with reporting, not whether attacks succeed; a rise can even accompany improved detection. It tempts because reporting volume suits evaluating a reporting button or mailbox rollout. Effectiveness at reducing successful phishing requires the click and credential-submission rate, or the resulting compromise count.
- ✗
Number of security incidents caused by phishing
Why it's wrong here
Phishing incident counts reflect real-world outcomes but are confounded by attack volume, reporting rates and detection coverage, so they cannot isolate training's effect. It is tempting because incident reduction is the program's ultimate goal; this metric suits measuring overall security posture, not the training intervention itself.
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.