SY0-701 - Security Program Management and Oversight (20% of the exam) - Section 5.6

Given a scenario, implement security awareness practices.

Design security awareness training programmes that use simulated phishing campaigns and user behaviour monitoring to reinforce secure practices and identify staff who need additional coaching. Apply anomalous behaviour recognition principles to ensure employees understand what to report and to whom, converting the human layer from a primary vulnerability into an active detection control.

phishing campaignssecurity awareness traininguser behaviorreporting and monitoringanomalous behavior recognition

Practice question for this objective

Free sampleSecurity Program Management and Oversighteasy

A regional council's security manager is briefing the executive on what the council should measure to know whether its security awareness programme is actually working. The chief executive has asked for a small set of indicators that reflect changes in user behaviour over time, not just whether staff have completed mandatory training. Which set of indicators most directly meets the chief executive's request?

  • AThe number of awareness modules published in the learning management system each quarter and the total length in minutes of all training content available to staff.
  • BThe completion rate of the annual mandatory module and the percentage of staff who scored above a fixed pass mark on the final quiz.
  • CThe phishing simulation click rate, the phishing report rate via the report-phishing button, the repeat-click rate for staff who failed previous simulations, and the volume of genuine suspicious messages reported by staff. Correct
  • DThe number of new security policies published each year and the count of policy exceptions granted, broken down by department.
Measure security awareness by user behaviour indicators such as click rate, report rate, repeat-click rate, and real-world report volume rather than by training completion alone. The SY0-701 objective treats reporting and monitoring as part of awareness practices. Behaviour-focused metrics, particularly those drawn from phishing simulations and the genuine reporting channel, give a defensible view of whether awareness work is changing how staff act, which training completion alone cannot show.

Why A is wrong: Content volume measures programme output, not user behaviour. A larger module catalogue is consistent with declining staff engagement and gives the executive no insight into whether behaviour is changing.

Why B is wrong: Completion and quiz scores measure attendance and short-term recall. They do not track whether staff are reporting phishing, recognising anomalies, or improving over time, which is what the chief executive specifically asked for.

Why C is correct: These four indicators directly measure user behaviour over time. Together they show whether staff are clicking less, reporting more, learning after a mistake, and applying the same reporting habit to real attacks, which is exactly what the chief executive asked for.

Why D is wrong: Policy and exception counts are governance metrics rather than awareness metrics. They tell the executive about document flow and exception management, not about how staff are behaving in their daily use of systems.

See more SY0-701 practice questions, answers explained.

Exam traps in Security Program Management and Oversight

Answers that look right on this material and are not. Each one is a distractor from a different question in the SY0-701 bank for this domain.

  • To penalise individual users who click the test messages and remove their email access until a manager intervenes.

    Why it is wrong: Tempting because some immature programmes do punish clickers, but the recognised purpose of a simulated phishing campaign is to measure susceptibility and direct training, not to act as a disciplinary mechanism that erodes the reporting culture the programme depends on.

  • Increase the length of the annual phishing module from thirty minutes to ninety minutes and add a final quiz with a higher pass mark before staff can access email.

    Why it is wrong: Longer modules and higher pass marks address recall of facts, not the reporting workflow. Staff in the scenario already recognise messages as suspicious; the failure is what they do next, which a longer slide deck does not change.

  • Keep the induction module at ninety minutes and add a second identical ninety-minute module at the staff member's annual appraisal so that the content is delivered twice.

    Why it is wrong: Doubling a single annual module preserves the same problem the chief information security officer is trying to solve. Long, infrequent sessions do not produce sustained behaviour change and are quickly forgotten between deliveries.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.