An information security manager introduces periodic simulated phishing exercises as part of the awareness programme. A staff representative asks what the simulations are primarily intended to achieve. What is the main purpose of running phishing simulations?
- ATo measure how staff respond to realistic lures and reinforce safe behaviour through timely, targeted follow-up training. Correct
- BTo generate disciplinary evidence so that employees who repeatedly fail the simulations can be formally sanctioned by management.
- CTo satisfy the auditors that a phishing control exists, allowing the manager to mark the awareness requirement as complete for the year.
- DTo test whether the email gateway and spam filtering technology can detect and quarantine the simulated phishing messages reliably.
Why A is correct: Correct because simulations reveal real susceptibility and create a teachable moment, letting the manager reinforce safe behaviour where it is weakest, which is the behavioural aim of awareness.
Why B is wrong: Using simulations to punish staff is tempting as an accountability lever, but a punitive aim discourages reporting and erodes trust, which works against the programme's behavioural goal.
Why C is wrong: Treating simulations as a compliance tick is tempting because it closes an audit finding, but running them only for evidence ignores their real value in changing how staff respond.
Why D is wrong: Testing the mail gateway is tempting because the simulation uses email, but that is a technical control test, whereas phishing simulations exist to assess and improve human behaviour.