CompTIA Security+ (SY0-701)Security OperationsEasy

A security team is implementing a security awareness program. They want to simulate real-world phishing attempts to educate employees on how to identify and report suspicious emails without causing actual harm. Which type of exercise would best achieve this goal?

  1. ATabletop exercise
  2. BSimulated phishing campaign
  3. CPenetration testing
  4. DVulnerability scanning
Show answer & explanation

Correct answer: B. Simulated phishing campaign

A simulated phishing campaign involves sending fake phishing emails to employees in a controlled environment. This directly trains them to recognize and report such attacks without exposing the organization to actual risk, aligning perfectly with the goal of educating employees on identifying suspicious emails.

Why the other options are wrong

  • A. A tabletop exercise is a discussion-based training that simulates an incident, but doesn't involve actual email interaction.
  • C. Penetration testing actively exploits vulnerabilities to test security controls, not primarily for employee education on phishing.
  • D. Vulnerability scanning identifies technical weaknesses in systems, not human susceptibility to social engineering.

Simulated Phishing Campaign

A controlled exercise where an organization sends fake phishing emails to its employees to test their awareness and ability to identify and report malicious attempts.

  • Educates employees on recognizing social engineering tactics.
  • Measures the effectiveness of security awareness training.
  • Helps identify employees who may need additional training.

Memory trick: To learn phishing, you need a 'Fake Phish' to practice.

More Security Operations questions