What Type of Attack is a Suspicious Email from the CEO?
A security awareness training program is being developed. Which topic is most important to include to reduce the risk of credential theft?
⚠ Common exam trap
Watch out — candidates often choose physical security procedures (Option B) because they associate credential theft with stolen hardware, but the SSCP exam emphasizes that the most common and effective method of credential theft is phishing, not physical access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Recognizing phishing attempts
Phishing is the primary vector for credential theft, as attackers use deceptive emails or messages to trick users into revealing usernames and passwords. Training users to recognize phishing attempts—such as spoofed sender addresses, suspicious URLs, and urgent language—directly mitigates this risk by preventing credential disclosure at the point of attack. Unlike other topics, phishing awareness specifically targets the social engineering techniques most commonly used to steal credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Proper use of social media
Why it's wrong here
Social media guidance reduces oversharing and reconnaissance, but the dominant credential-theft vector is phishing messages and password reuse, which this topic does not address. Social media awareness is the right inclusion when the risk being mitigated is impersonation or information disclosure through public posts.
- ✗
Physical security procedures
Why it's wrong here
Physical security controls protect facilities and hardware, not user credentials harvested through phishing or reuse. It is tempting because awareness programmes do cover tailgating and visitor badges, and that content is the correct answer when the stated risk is unauthorised physical access to systems.
- ✓
Recognizing phishing attempts
Why this is correct
Phishing is the leading vector for stolen credentials, tricking users into surrendering passwords on fraudulent pages. Training staff to recognise suspicious senders, links and urgent requests directly reduces that risk, addressing the credential-theft constraint more effectively than general policy or password topics.
- ✗
Data backup procedures
Why it's wrong here
Backups restore data after loss; they neither prevent credential harvesting nor detect compromised accounts. Including backup procedures is tempting because resilience training features in most awareness curricula, and it is the correct topic when the objective is recovering from ransomware or accidental deletion.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are examples of security awareness training topics?
easy- A.How to apply patches to servers
- ✓ B.Recognizing phishing emails
- C.Configuring firewall rules
- ✓ D.Physical security best practices (e.g., locking screens)
- ✓ E.Social engineering tactics
Why B: Security awareness training targets the general workforce's day-to-day behavior rather than specialized technical administration. Option B (Recognizing phishing emails) is correct because teaching users to spot suspicious senders, spoofed links, and urgent lures is a core awareness objective that reduces credential theft and malware infections. Option D (Physical security best practices such as locking screens) is correct because awareness programs cover everyday physical controls like clean-desk policies, tailgating prevention, and screen locking to protect data from unauthorized access. Option E (Social engineering tactics) is correct because understanding pretexting, baiting, and impersonation helps employees resist manipulation attempts that bypass technical controls. Options A (applying server patches) and C (configuring firewall rules) are not awareness topics; they are hands-on technical administration tasks performed by IT/security staff, not general-user training content.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.