CompTIA Security+ (SY0-701)Security OperationsMedium

A company is implementing a security awareness program. They want to simulate real-world phishing attacks to assess employee susceptibility and provide targeted training based on the results. Which activity would best achieve this goal?

  1. AImplementing a Security Information and Event Management (SIEM) system
  2. BConducting a penetration test
  3. CDeploying a honeypot
  4. DRunning a simulated phishing campaign
Show answer & explanation

Correct answer: D. Running a simulated phishing campaign

A simulated phishing campaign involves sending fake phishing emails to employees to test their awareness and reaction. This directly assesses employee susceptibility to phishing and provides data for targeted training, aligning perfectly with the goal.

Why the other options are wrong

  • A. A SIEM system collects and analyzes security logs, which is a technical control, not a method for assessing employee awareness.
  • B. A penetration test assesses the security of systems and networks, not directly employee susceptibility to social engineering.
  • C. Deploying a honeypot is for luring and monitoring attackers, not for assessing employee awareness.

Simulated Phishing Campaign

An exercise where an organization sends controlled, fake phishing emails to its employees to test their awareness and response to social engineering attacks.

  • Measures employee susceptibility to phishing.
  • Identifies training gaps and areas for improvement.
  • Provides data to tailor security awareness training.

Memory trick: Phishing simulation: 'Phish' for employee reactions.

More Security Operations questions