Cisco CCNP Security Core (SCOR) 350-701Security ConceptsMedium
A company is experiencing an increase in phishing attacks targeting its employees. To combat this, they decide to launch a series of simulated phishing campaigns and provide interactive training modules to help employees recognize and report suspicious emails. Which security best practice are they primarily implementing?
- ASecurity awareness training
- BPatch management
- CAccess control implementation
- DVulnerability management
Show answer & explanationAnswer & explanation
Correct answer: A. Security awareness training
The scenario describes activities like 'simulated phishing campaigns' and 'interactive training modules to help employees recognize and report suspicious emails', all of which are core components of effective security awareness training.
Why the other options are wrong
- B. Patch management applies software updates to fix vulnerabilities, not train users.
- C. Access control restricts who can access resources, not how users identify threats.
- D. Vulnerability management focuses on finding and fixing software/system flaws, not user education.
Security Awareness Training
A program designed to educate employees about cybersecurity risks, policies, and best practices to foster a security-conscious culture and reduce human-related vulnerabilities.
- Often includes phishing simulations, policy reviews, and interactive modules.
- Aims to make employees the 'first line of defense'.
- Should be continuous and adapt to evolving threats.
Memory trick: Humans are the weakest link, so train them right!