CompTIA Security+ (SY0-701)Security OperationsEasy
A company is implementing a security awareness program. They want to simulate real-world phishing attacks to assess employee susceptibility and provide targeted training. Which of the following activities would BEST achieve this goal?
- ADistributing pamphlets on password best practices
- BPerforming simulated phishing campaigns
- CConducting annual security policy reviews
- DImplementing multi-factor authentication (MFA) for all users
Show answer & explanationAnswer & explanation
Correct answer: B. Performing simulated phishing campaigns
Simulated phishing campaigns are designed to mimic real-world phishing attacks, allowing organizations to measure employee susceptibility, identify training gaps, and provide immediate, targeted education to those who fall for the simulations.
Why the other options are wrong
- A. Pamphlets are a passive form of education and don't practically test or improve employee awareness against live threats.
- C. Annual policy reviews educate employees on rules but don't assess their practical ability to identify threats.
- D. MFA is a technical control to enhance security, but it does not assess or improve employee awareness of phishing attempts themselves.
Simulated Phishing Campaign
A controlled exercise where an organization sends fake phishing emails to employees to test their ability to identify and report such attacks, and to provide targeted training.
- Measures human vulnerability
- Provides practical, experiential learning
- Identifies training needs
Memory trick: Awareness is about training minds, not just tech.