SY0-701 Question 477
Single answer5.6 Given a scenario, implement security awareness practices.A company has seen an increase in successful phishing attacks after several employees clicked links in emails that appeared to come from the HR department. The security manager wants to improve user behavior without disrupting business operations or relying only on annual compliance training. Which action would BEST reduce the likelihood of future phishing success?
- A
Implement a recurring phishing simulation and targeted just-in-time training for employees who click the simulated messages
- B
Require all employees to sign the acceptable use policy again at the end of the quarter
- C
Block all external email messages that contain hyperlinks
- D
Send a company-wide memo reminding users to be more careful with email
Show answer and explanation
Correct answer: A
Explanation
The best answer is to implement recurring phishing simulations with targeted just-in-time training. In Security+ objectives related to security awareness practices, organizations are expected to use practical, behavior-focused methods such as phishing campaigns, role-based awareness, and continuous reinforcement instead of relying solely on annual training. This approach aligns with common best practices from sources such as NIST guidance on awareness and training, which emphasizes ongoing, relevant, and measurable user education. The other options either focus on compliance acknowledgment, create excessive business disruption, or provide low-value awareness messaging without testing or improving employee behavior.
- A. Correct.
Correct. Recurring phishing simulations paired with targeted, timely follow-up training are a well-established security awareness practice. This approach reinforces recognition of phishing indicators in a realistic context, provides measurable results, and focuses remediation on users who need it most. It is more effective than passive reminders because it changes behavior through practice and feedback.
- B. Incorrect.
Incorrect. Re-signing an acceptable use policy may help with policy acknowledgment, but it does not meaningfully improve phishing detection skills. This option addresses administrative compliance rather than practical security awareness behavior.
- C. Incorrect.
Incorrect. Blocking all external emails with hyperlinks would severely disrupt normal business communication and is not a realistic or balanced control for most organizations. It also shifts the problem to technical filtering rather than improving user awareness, which is the focus of the scenario.
- D. Incorrect.
Incorrect. A reminder memo is a weak awareness measure because it is generic, not interactive, and does not validate whether employees can identify phishing attempts. Users may read the memo and still fail to apply the guidance in real situations.