CompTIA Security+ (SY0-701)Security OperationsEasy
A company is implementing a new security awareness program. They want to simulate real-world phishing attempts to gauge employee susceptibility and identify areas for further training without causing actual harm. What type of exercise would BEST achieve this goal?
- ASimulated phishing campaign
- BPenetration testing
- CSecurity audit
- DVulnerability scanning
Show answer & explanationAnswer & explanation
Correct answer: A. Simulated phishing campaign
A simulated phishing campaign involves sending controlled, fake phishing emails to employees. This allows the organization to measure how many employees fall for the phish, click malicious links, or enter credentials, providing valuable metrics for targeted security awareness training.
Why the other options are wrong
- B. Penetration testing simulates attacks on systems and networks to find exploitable vulnerabilities, not to test employee awareness of phishing.
- C. A security audit assesses compliance with policies and standards, not directly employee behavior regarding phishing.
- D. Vulnerability scanning identifies technical weaknesses in systems, not human susceptibility to social engineering.
Simulated Phishing Campaign
A controlled exercise where fake phishing emails are sent to employees to test their awareness and identify training needs.
- Measures employee susceptibility to social engineering.
- Identifies individuals needing more training.
- Provides metrics for security awareness program effectiveness.
Memory trick: To CATCH a phish, you have to GO FISHING, but with a FAKE WORM.