SY0-701 exam dumps

SY0-701 practice question 2 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 2

Single answer1.1 Compare and contrast various types of security controls.

A healthcare company is preparing for an audit after several employees were tricked by phishing emails that led to credential theft. Management wants to reduce the likelihood of similar incidents by changing employee behavior, while also demonstrating to auditors that the organization has implemented a formal security control specifically intended to influence user actions. Which of the following is the BEST choice?

  1. A

    Deploy an email sandbox to detonate attachments before delivery

  2. B

    Require annual security awareness and phishing simulation training for all staff

  3. C

    Implement account lockout thresholds after repeated failed logon attempts

  4. D

    Enable full-disk encryption on all company laptops

Show answer and explanation

Correct answer: B

Explanation

This question tests the ability to compare security controls by category and purpose rather than simply identifying a technology. In Security+, candidates should distinguish administrative, technical, and physical controls, as well as functional types such as preventive, detective, corrective, deterrent, compensating, and directive. In this scenario, the organization wants a control that specifically influences employee actions after phishing incidents. Security awareness training is an administrative control and is commonly used as a directive or deterrent measure to shape user behavior. It is also frequently reviewed during audits as part of an organization's security program. By contrast, email sandboxing and account lockout are technical controls, and full-disk encryption protects data at rest rather than addressing user susceptibility to phishing. This aligns with common best practices reflected in security awareness guidance from NIST, including training and awareness concepts in NIST SP 800-50, and broader control frameworks that separate administrative and technical safeguards.

  • A. Incorrect.

    Deploying an email sandbox is a technical preventive/detective control that helps identify and block malicious attachments or links before they reach users. While it reduces phishing risk, it does not primarily function as a formal control intended to influence employee behavior. A candidate might choose this because it directly addresses phishing, but the question specifically asks for a control designed to change user actions.

  • B. Correct.

    Annual security awareness and phishing simulation training is the best answer because it is an administrative control and, more specifically, a deterrent/directive style of control used to influence user behavior and reduce the chance that employees will fall for phishing attempts. It also provides clear evidence to auditors that the organization has implemented a formal program to guide employee actions.

  • C. Incorrect.

    Account lockout thresholds are technical preventive controls that can reduce brute-force password attacks or limit repeated login attempts. However, they do not directly address the root issue in the scenario: employees being socially engineered through phishing. This option is plausible because compromised credentials are involved, but it does not primarily change user behavior.

  • D. Incorrect.

    Full-disk encryption is a corrective/compensating safeguard for protecting data at rest if a device is lost or stolen. It is an important control in many environments, especially healthcare, but it does not reduce phishing susceptibility or serve as a control intended to direct user behavior. Someone might choose it because healthcare data is sensitive, but it does not fit the scenario.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam