CompTIA Security+ (SY0-701)Security Program Management and OversightHard

After a six-month phishing simulation and awareness campaign, click rates on simulated phishing emails dropped from 25% to 8%, while the rate of employees reporting suspicious emails to security increased from 5% to 30%. Which conclusion best reflects the effectiveness of the awareness program?

  1. AThe training is effective, as shown by both reduced clicks and increased reporting behavior
  2. BThe results are inconclusive without knowing the annualized rate of occurrence
  3. CThe training is ineffective because the click rate is not zero
  4. DThe program should be discontinued since more employees are now reporting emails
Show answer & explanation

Correct answer: A. The training is effective, as shown by both reduced clicks and increased reporting behavior

A meaningful decrease in click-through rate combined with a significant increase in reporting behavior demonstrates that employees are both less susceptible to phishing and more actively participating in defense, both strong indicators of an effective awareness program.

Why the other options are wrong

  • B. ARO relates to quantitative risk calculations, not awareness program effectiveness metrics.
  • C. Zero click rate is unrealistic; the significant reduction itself shows improvement.
  • D. Increased reporting is a positive outcome, not a reason to discontinue the program.

Security Awareness Metrics

Effectiveness of security awareness training is measured by trends such as decreasing phishing click rates and increasing suspicious email reporting rates.

  • Lower click-through rate indicates reduced susceptibility
  • Higher reporting rate indicates increased vigilance
  • Both metrics together provide a fuller picture than either alone

Memory trick: Fewer Bites, More Reports = Awareness Works

More Security Program Management and Oversight questions