CompTIA Security+ (SY0-701)Security OperationsEasy

A company is implementing a security awareness program. They want to simulate real-world phishing attacks to assess employee susceptibility and provide targeted training. Which of the following activities would BEST achieve this goal?

  1. ADistributing pamphlets on password best practices
  2. BPerforming simulated phishing campaigns
  3. CConducting annual security policy reviews
  4. DImplementing multi-factor authentication (MFA) for all users
Show answer & explanation

Correct answer: B. Performing simulated phishing campaigns

Simulated phishing campaigns are designed to mimic real-world phishing attacks, allowing organizations to measure employee susceptibility, identify training gaps, and provide immediate, targeted education to those who fall for the simulations.

Why the other options are wrong

  • A. Pamphlets are a passive form of education and don't practically test or improve employee awareness against live threats.
  • C. Annual policy reviews educate employees on rules but don't assess their practical ability to identify threats.
  • D. MFA is a technical control to enhance security, but it does not assess or improve employee awareness of phishing attempts themselves.

Simulated Phishing Campaign

A controlled exercise where an organization sends fake phishing emails to employees to test their ability to identify and report such attacks, and to provide targeted training.

  • Measures human vulnerability
  • Provides practical, experiential learning
  • Identifies training needs

Memory trick: Awareness is about training minds, not just tech.

More Security Operations questions