During onboarding at Jarrah Consulting, the security lead wants new hires to recognise phishing emails, choose strong passphrases, and understand how to report suspicious activity. Which programme is designed to deliver this understanding across the general workforce?
- AA penetration testing engagement in which specialists attempt to breach systems to find exploitable weaknesses
- BA vulnerability management process that scans systems and prioritises the flaws that need patching
- CA security awareness training programme that educates all staff on recognising and responding to everyday threats Correct
- DA disaster recovery exercise that rehearses restoring critical systems and data after a serious outage
Why A is wrong: Penetration testing probes technical defences and is performed by specialists, so it does not educate general staff about everyday threats such as phishing.
Why B is wrong: Vulnerability management identifies and remediates technical weaknesses in systems, not the human behaviours that awareness training is meant to shape.
Why C is correct: Security awareness training targets the whole workforce and covers recognising phishing, good password habits, and reporting, matching exactly what the lead wants delivered.
Why D is wrong: A disaster recovery exercise practises recovering operations after disruption, which is valuable but does not teach staff to spot phishing or choose passphrases.