SY0-701 - Security Program Management and Oversight - Section 5.6

Given a scenario, implement security awareness practices.

Design security awareness training programmes that use simulated phishing campaigns and user behaviour monitoring to reinforce secure practices and identify staff who need additional coaching. Apply anomalous behaviour recognition principles to ensure employees understand what to report and to whom, converting the human layer from a primary vulnerability into an active detection control.

phishing campaignssecurity awareness traininguser behaviorreporting and monitoringanomalous behavior recognition

Practice question for this objective

Free sampleSecurity Program Management and Oversighteasy

A regional council's security manager is briefing the executive on what the council should measure to know whether its security awareness programme is actually working. The chief executive has asked for a small set of indicators that reflect changes in user behaviour over time, not just whether staff have completed mandatory training. Which set of indicators most directly meets the chief executive's request?

  • AThe number of awareness modules published in the learning management system each quarter and the total length in minutes of all training content available to staff.
  • BThe completion rate of the annual mandatory module and the percentage of staff who scored above a fixed pass mark on the final quiz.
  • CThe phishing simulation click rate, the phishing report rate via the report-phishing button, the repeat-click rate for staff who failed previous simulations, and the volume of genuine suspicious messages reported by staff. Correct
  • DThe number of new security policies published each year and the count of policy exceptions granted, broken down by department.
Measure security awareness by user behaviour indicators such as click rate, report rate, repeat-click rate, and real-world report volume rather than by training completion alone. The SY0-701 objective treats reporting and monitoring as part of awareness practices. Behaviour-focused metrics, particularly those drawn from phishing simulations and the genuine reporting channel, give a defensible view of whether awareness work is changing how staff act, which training completion alone cannot show.

Why A is wrong: Content volume measures programme output, not user behaviour. A larger module catalogue is consistent with declining staff engagement and gives the executive no insight into whether behaviour is changing.

Why B is wrong: Completion and quiz scores measure attendance and short-term recall. They do not track whether staff are reporting phishing, recognising anomalies, or improving over time, which is what the chief executive specifically asked for.

Why C is correct: These four indicators directly measure user behaviour over time. Together they show whether staff are clicking less, reporting more, learning after a mistake, and applying the same reporting habit to real attacks, which is exactly what the chief executive asked for.

Why D is wrong: Policy and exception counts are governance metrics rather than awareness metrics. They tell the executive about document flow and exception management, not about how staff are behaving in their daily use of systems.

See more SY0-701 practice questions, answers explained.

More in this domain

Back to all Security Program Management and Oversight objectives, or the SY0-701 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.