CompTIA Security+ (SY0-701)Security OperationsMedium
A security team is implementing a new security awareness program. They want to simulate real-world phishing attacks to gauge employee susceptibility and identify areas for further training. Which type of exercise should they conduct?
- APenetration test
- BVulnerability scan
- CTabletop exercise
- DSimulated phishing campaign
Show answer & explanationAnswer & explanation
Correct answer: D. Simulated phishing campaign
A simulated phishing campaign involves sending controlled, fake phishing emails to employees to test their ability to identify and report such attempts. This directly measures susceptibility to social engineering and helps tailor training.
Why the other options are wrong
- A. A penetration test actively exploits vulnerabilities to assess system security, which is different from testing employee awareness of phishing.
- B. A vulnerability scan identifies technical weaknesses in systems, not human susceptibility to social engineering.
- C. A tabletop exercise is a discussion-based drill to review incident response plans, not to assess individual employee susceptibility to attacks.
Simulated Phishing Campaign
A controlled exercise where an organization sends fake phishing emails to its employees to test their awareness, identify vulnerabilities, and provide targeted training.
- Measures employee susceptibility to social engineering.
- Identifies training gaps.
- Helps reinforce security best practices.
Memory trick: To test for 'Phishing' awareness, you need a 'Simulated Phishing' attack.