Topic 28 Practice Test 1 covers Security Awareness Practices for CompTIA Security+ SY0-701 and maps to objective 5.6: Given a scenario, implement security awareness practices. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
A security plan created during a security-awareness program review must provide ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies, defined method for users to submit potentially malicious messages to security teams, and training that helps users recognize security context and adjust behavior to changing circumstances. Which THREE options should be selected? Choose THREE.
- Remote-work security training
- Unintentional behavior awareness
- Suspicious-message reporting
- Situational awareness training
- Phishing recognition
- Removable-media training
Correct Answers: C, D, E
Correct Answers
Answer C is correct because Suspicious-message reporting means a defined method for users to submit potentially malicious messages to security teams. The fixed-count item needs this function in the answer set. Remote-work security training covers guidance on protecting devices, networks, conversations, and data outside controlled offices, a different requirement.
Answer D is correct because Situational awareness training means training that helps users recognize security context and adjust behavior to changing circumstances. It belongs in the fixed-count answer set because it covers one of the stated requirements. Remote-work security training instead serves guidance on protecting devices, networks, conversations, and data outside controlled offices and cannot replace this function.
Answer E is correct because Phishing recognition means ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. It belongs in the fixed-count answer set because it covers one of the stated requirements. Removable-media training instead serves guidance on safe handling of USB drives and other portable media and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Remote-work security training means guidance on protecting devices, networks, conversations, and data outside controlled offices. The fixed-count answer set is Suspicious-message reporting, Situational awareness training, Phishing recognition; this option does not fill one of those named functions.
Answer B is incorrect because Unintentional behavior awareness means training that addresses mistakes and accidental actions that can create security incidents. The question requires exactly 3 selections: Suspicious-message reporting, Situational awareness training, Phishing recognition. This option falls outside that required set.
Answer F is incorrect because Removable-media training means guidance on safe handling of USB drives and other portable media. The required choices are Suspicious-message reporting, Situational awareness training, Phishing recognition. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 2
To help employees identify concerning behavior without encouraging unsupported accusations, which security approach should be selected?
- Password-management training
- Risky behavior recognition
- Insider-threat awareness
- Unintentional behavior awareness
Correct Answer: C
Correct Answer
Answer C is correct because Insider-threat awareness means education on indicators and reporting related to malicious or negligent trusted users. That makes it the best answer here; Password-management training addresses guidance on unique credentials, password managers, MFA, and safe credential handling, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling. The scenario instead requires education on indicators and reporting related to malicious or negligent trusted users, which is why Insider-threat awareness is the better answer; this option serves the different function defined above.
Answer B is incorrect because Risky behavior recognition refers to awareness of actions that materially increase security exposure. The scenario instead requires education on indicators and reporting related to malicious or negligent trusted users, which is why Insider-threat awareness is the better answer; this option serves the different function defined above.
Answer D is incorrect because Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents. This could be appropriate elsewhere, but the required function is education on indicators and reporting related to malicious or negligent trusted users; that makes Insider-threat awareness the precise choice.
Question 3
Which term describes training that addresses mistakes and accidental actions that can create security incidents?
- Phishing simulation campaign
- Phishing recognition
- Policy and handbook training
- Unintentional behavior awareness
Correct Answer: D
Correct Answer
Answer D is correct because Unintentional behavior awareness means training that addresses mistakes and accidental actions that can create security incidents. That makes it the best answer here; Phishing recognition addresses ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Phishing simulation campaign refers to authorized simulated phishing used to measure and improve user recognition and reporting behavior. The concept is valid, but it does not match this stem. The required function is training that addresses mistakes and accidental actions that can create security incidents, which maps to Unintentional behavior awareness.
Answer B is incorrect because Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. The scenario instead requires training that addresses mistakes and accidental actions that can create security incidents, which is why Unintentional behavior awareness is the better answer; this option serves the different function defined above.
Answer C is incorrect because Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior. The concept is valid, but it does not match this stem. The required function is training that addresses mistakes and accidental actions that can create security incidents, which maps to Unintentional behavior awareness.
Question 4
Which term describes education on indicators and reporting related to malicious or negligent trusted users?
- Insider-threat awareness
- Suspicious-message reporting
- Unintentional behavior awareness
- Social-engineering training
Correct Answer: A
Correct Answer
Answer A is correct because Insider-threat awareness means education on indicators and reporting related to malicious or negligent trusted users. The requirement maps directly to this function, whereas Unintentional behavior awareness is aimed at training that addresses mistakes and accidental actions that can create security incidents.
Incorrect Answers
Answer B is incorrect because Suspicious-message reporting refers to a defined method for users to submit potentially malicious messages to security teams. The question is not asking for this function. It is testing education on indicators and reporting related to malicious or negligent trusted users, so Insider-threat awareness is the stronger fit.
Answer C is incorrect because Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents. The scenario instead requires education on indicators and reporting related to malicious or negligent trusted users, which is why Insider-threat awareness is the better answer; this option serves the different function defined above.
Answer D is incorrect because Social-engineering training refers to education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. The key mismatch is functional: Insider-threat awareness addresses education on indicators and reporting related to malicious or negligent trusted users, the need stated by the question.
Question 5
An architect working on a security-awareness program review needs one capability that provides ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies and another that provides guidance on protecting devices, networks, conversations, and data outside controlled offices. Which TWO selections are the best match? Choose TWO.
- Removable-media training
- Phishing recognition
- Remote-work security training
- Policy and handbook training
- Recurring awareness training
Correct Answers: B, C
Correct Answers
Answer B is correct because Phishing recognition means ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. It belongs in the fixed-count answer set because it covers one of the stated requirements. Removable-media training instead serves guidance on safe handling of USB drives and other portable media and cannot replace this function. This question specifically tests the combined requirements represented by Phishing recognition and Remote-work security training.
Answer C is correct because Remote-work security training means guidance on protecting devices, networks, conversations, and data outside controlled offices. This selection maps directly to one of the named needs. Policy and handbook training addresses education on organizational rules, responsibilities, and expected security behavior, so it does not satisfy the same slot.
Incorrect Answers
Answer A is incorrect because Removable-media training means guidance on safe handling of USB drives and other portable media. The question requires exactly 2 selections: Phishing recognition, Remote-work security training. This option falls outside that required set. For example, Remote-work security training is required for guidance on protecting devices, networks, conversations, and data outside controlled offices.
Answer D is incorrect because Policy and handbook training means education on organizational rules, responsibilities, and expected security behavior. Every answer slot must map to a stated requirement. The correct set is Phishing recognition, Remote-work security training, so this option cannot replace one of those selections.
Answer E is incorrect because Recurring awareness training means security education repeated periodically and updated for changing threats and policies. The scenario calls for Phishing recognition, Remote-work security training. Selecting this option would leave one of those required functions uncovered.
Question 6
Which term describes security education repeated periodically and updated for changing threats and policies?
- Recurring awareness training
- Operational security awareness
- Social-engineering training
- Phishing recognition
Correct Answer: A
Correct Answer
Answer A is correct because Recurring awareness training means security education repeated periodically and updated for changing threats and policies. That makes it the best answer here; Phishing recognition addresses ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because Operational security awareness refers to training on avoiding unnecessary exposure of sensitive operational details. The concept is valid, but it does not match this stem. The required function is security education repeated periodically and updated for changing threats and policies, which maps to Recurring awareness training.
Answer C is incorrect because Social-engineering training refers to education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. The question is not asking for this function. It is testing security education repeated periodically and updated for changing threats and policies, so Recurring awareness training is the stronger fit.
Answer D is incorrect because Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. The scenario instead requires security education repeated periodically and updated for changing threats and policies, which is why Recurring awareness training is the better answer; this option serves the different function defined above.
Question 7
To reduce security risk in home, travel, and hybrid work environments, which security approach should be selected?
- Password-management training
- Situational awareness training
- Remote-work security training
- Phishing simulation campaign
Correct Answer: C
Correct Answer
Answer C is correct because Remote-work security training means guidance on protecting devices, networks, conversations, and data outside controlled offices. The deciding point is functional fit: this option covers the stated need, while Password-management training addresses guidance on unique credentials, password managers, MFA, and safe credential handling.
Incorrect Answers
Answer A is incorrect because Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling. The key mismatch is functional: Remote-work security training addresses guidance on protecting devices, networks, conversations, and data outside controlled offices, the need stated by the question.
Answer B is incorrect because Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances. The key mismatch is functional: Remote-work security training addresses guidance on protecting devices, networks, conversations, and data outside controlled offices, the need stated by the question.
Answer D is incorrect because Phishing simulation campaign refers to authorized simulated phishing used to measure and improve user recognition and reporting behavior. The scenario instead requires guidance on protecting devices, networks, conversations, and data outside controlled offices, which is why Remote-work security training is the better answer; this option serves the different function defined above.
Question 8
To help users resist nontechnical attacks that target human trust, which security approach should be selected?
- Situational awareness training
- Social-engineering training
- Removable-media training
- Unexpected behavior recognition
Correct Answer: B
Correct Answer
Answer B is correct because Social-engineering training means education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. This matches the requirement as written. Unexpected behavior recognition can be valid in another context, but it is used for awareness that unusual system, message, or identity behavior may indicate a security issue.
Incorrect Answers
Answer A is incorrect because Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances. That concept can be valid in another scenario, but this question is testing education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure; Social-engineering training therefore fits the requirement more directly.
Answer C is incorrect because Removable-media training refers to guidance on safe handling of USB drives and other portable media. The key mismatch is functional: Social-engineering training addresses education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure, the need stated by the question.
Answer D is incorrect because Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue. That concept can be valid in another scenario, but this question is testing education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure; Social-engineering training therefore fits the requirement more directly.
Question 9
During a security-awareness program review, the team has two independent requirements: (1) training that addresses mistakes and accidental actions that can create security incidents; and (2) guidance on protecting devices, networks, conversations, and data outside controlled offices. Which TWO choices best satisfy those requirements? Choose TWO.
- Unexpected behavior recognition
- Unintentional behavior awareness
- Insider-threat awareness
- Remote-work security training
- Phishing recognition
Correct Answers: B, D
Correct Answers
Answer B is correct because Unintentional behavior awareness means training that addresses mistakes and accidental actions that can create security incidents. It belongs in the fixed-count answer set because it covers one of the stated requirements. Insider-threat awareness instead serves education on indicators and reporting related to malicious or negligent trusted users and cannot replace this function.
Answer D is correct because Remote-work security training means guidance on protecting devices, networks, conversations, and data outside controlled offices. It belongs in the fixed-count answer set because it covers one of the stated requirements. Phishing recognition instead serves ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Unexpected behavior recognition means awareness that unusual system, message, or identity behavior may indicate a security issue. Every answer slot must map to a stated requirement. The correct set is Remote-work security training, Unintentional behavior awareness, so this option cannot replace one of those selections.
Answer C is incorrect because Insider-threat awareness means education on indicators and reporting related to malicious or negligent trusted users. The fixed-count answer set is Remote-work security training, Unintentional behavior awareness; this option does not fill one of those named functions.
Answer E is incorrect because Phishing recognition means ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. The required choices are Remote-work security training, Unintentional behavior awareness. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 10
To help users identify practices that could lead to compromise, which security approach should be selected?
- Password-management training
- Unexpected behavior recognition
- Risky behavior recognition
- Situational awareness training
Correct Answer: C
Correct Answer
Answer C is correct because Risky behavior recognition means awareness of actions that materially increase security exposure. The deciding point is functional fit: this option covers the stated need, while Situational awareness training addresses training that helps users recognize security context and adjust behavior to changing circumstances.
Incorrect Answers
Answer A is incorrect because Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling. This could be appropriate elsewhere, but the required function is awareness of actions that materially increase security exposure; that makes Risky behavior recognition the precise choice.
Answer B is incorrect because Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue. The scenario instead requires awareness of actions that materially increase security exposure, which is why Risky behavior recognition is the better answer; this option serves the different function defined above.
Answer D is incorrect because Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances. The question is not asking for this function. It is testing awareness of actions that materially increase security exposure, so Risky behavior recognition is the stronger fit.
Question 11
Which term describes authorized simulated phishing used to measure and improve user recognition and reporting behavior?
- Insider-threat awareness
- Password-management training
- Risky behavior recognition
- Phishing simulation campaign
Correct Answer: D
Correct Answer
Answer D is correct because Phishing simulation campaign means authorized simulated phishing used to measure and improve user recognition and reporting behavior. That makes it the best answer here; Password-management training addresses guidance on unique credentials, password managers, MFA, and safe credential handling, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Insider-threat awareness refers to education on indicators and reporting related to malicious or negligent trusted users. The scenario instead requires authorized simulated phishing used to measure and improve user recognition and reporting behavior, which is why Phishing simulation campaign is the better answer; this option serves the different function defined above.
Answer B is incorrect because Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling. The question is not asking for this function. It is testing authorized simulated phishing used to measure and improve user recognition and reporting behavior, so Phishing simulation campaign is the stronger fit.
Answer C is incorrect because Risky behavior recognition refers to awareness of actions that materially increase security exposure. The key mismatch is functional: Phishing simulation campaign addresses authorized simulated phishing used to measure and improve user recognition and reporting behavior, the need stated by the question.
Question 12
A review during a security-awareness program review identifies two gaps. One requires education on organizational rules, responsibilities, and expected security behavior. The other requires education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. Which TWO options should be included in the remediation plan? Choose TWO.
- Social-engineering training
- Situational awareness training
- Suspicious-message reporting
- Removable-media training
- Policy and handbook training
Correct Answers: A, E
Correct Answers
Answer A is correct because Social-engineering training means education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. It belongs in the fixed-count answer set because it covers one of the stated requirements. Removable-media training instead serves guidance on safe handling of USB drives and other portable media and cannot replace this function.
Answer E is correct because Policy and handbook training means education on organizational rules, responsibilities, and expected security behavior. This option satisfies a specific requirement in the stem; Situational awareness training serves training that helps users recognize security context and adjust behavior to changing circumstances and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because Situational awareness training means training that helps users recognize security context and adjust behavior to changing circumstances. The question requires exactly 2 selections: Policy and handbook training, Social-engineering training. This option falls outside that required set.
Answer C is incorrect because Suspicious-message reporting means a defined method for users to submit potentially malicious messages to security teams. Every answer slot must map to a stated requirement. The correct set is Policy and handbook training, Social-engineering training, so this option cannot replace one of those selections.
Answer D is incorrect because Removable-media training means guidance on safe handling of USB drives and other portable media. The required choices are Policy and handbook training, Social-engineering training. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 13
To improve decisions when working in public, remote, or unusual environments, which security approach should be selected?
- Password-management training
- Situational awareness training
- Unintentional behavior awareness
- Social-engineering training
Correct Answer: B
Correct Answer
Answer B is correct because Situational awareness training means training that helps users recognize security context and adjust behavior to changing circumstances. The deciding point is functional fit: this option covers the stated need, while Password-management training addresses guidance on unique credentials, password managers, MFA, and safe credential handling.
Incorrect Answers
Answer A is incorrect because Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling. This could be appropriate elsewhere, but the required function is training that helps users recognize security context and adjust behavior to changing circumstances; that makes Situational awareness training the precise choice.
Answer C is incorrect because Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents. That concept can be valid in another scenario, but this question is testing training that helps users recognize security context and adjust behavior to changing circumstances; Situational awareness training therefore fits the requirement more directly.
Answer D is incorrect because Social-engineering training refers to education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. That concept can be valid in another scenario, but this question is testing training that helps users recognize security context and adjust behavior to changing circumstances; Situational awareness training therefore fits the requirement more directly.
Question 14
To reduce compromise caused by weak, reused, or mishandled passwords, which security approach should be selected?
- Password-management training
- Situational awareness training
- Removable-media training
- Remote-work security training
Correct Answer: A
Correct Answer
Answer A is correct because Password-management training means guidance on unique credentials, password managers, MFA, and safe credential handling. This is the precise fit for the scenario. Remote-work security training serves the different purpose of guidance on protecting devices, networks, conversations, and data outside controlled offices.
Incorrect Answers
Answer B is incorrect because Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances. The concept is valid, but it does not match this stem. The required function is guidance on unique credentials, password managers, MFA, and safe credential handling, which maps to Password-management training.
Answer C is incorrect because Removable-media training refers to guidance on safe handling of USB drives and other portable media. The key mismatch is functional: Password-management training addresses guidance on unique credentials, password managers, MFA, and safe credential handling, the need stated by the question.
Answer D is incorrect because Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices. The concept is valid, but it does not match this stem. The required function is guidance on unique credentials, password managers, MFA, and safe credential handling, which maps to Password-management training.
Question 15
An architect working on a security-awareness program review needs one capability that provides education on indicators and reporting related to malicious or negligent trusted users and another that provides guidance on protecting devices, networks, conversations, and data outside controlled offices. Which TWO selections are the best match? Choose TWO.
- Situational awareness training
- Insider-threat awareness
- Social-engineering training
- Remote-work security training
- Risky behavior recognition
Correct Answers: B, D
Correct Answers
Answer B is correct because Insider-threat awareness means education on indicators and reporting related to malicious or negligent trusted users. This selection maps directly to one of the named needs. Risky behavior recognition addresses awareness of actions that materially increase security exposure, so it does not satisfy the same slot.
Answer D is correct because Remote-work security training means guidance on protecting devices, networks, conversations, and data outside controlled offices. This selection maps directly to one of the named needs. Situational awareness training addresses training that helps users recognize security context and adjust behavior to changing circumstances, so it does not satisfy the same slot.
Incorrect Answers
Answer A is incorrect because Situational awareness training means training that helps users recognize security context and adjust behavior to changing circumstances. Every answer slot must map to a stated requirement. The correct set is Insider-threat awareness, Remote-work security training, so this option cannot replace one of those selections.
Answer C is incorrect because Social-engineering training means education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. Every answer slot must map to a stated requirement. The correct set is Insider-threat awareness, Remote-work security training, so this option cannot replace one of those selections.
Answer E is incorrect because Risky behavior recognition means awareness of actions that materially increase security exposure. Every answer slot must map to a stated requirement. The correct set is Insider-threat awareness, Remote-work security training, so this option cannot replace one of those selections.
Question 16
To reduce incidents caused by error rather than malicious intent, which security approach should be selected?
- Suspicious-message reporting
- Unintentional behavior awareness
- Phishing simulation campaign
- Situational awareness training
Correct Answer: B
Correct Answer
Answer B is correct because Unintentional behavior awareness means training that addresses mistakes and accidental actions that can create security incidents. The requirement maps directly to this function, whereas Situational awareness training is aimed at training that helps users recognize security context and adjust behavior to changing circumstances.
Incorrect Answers
Answer A is incorrect because Suspicious-message reporting refers to a defined method for users to submit potentially malicious messages to security teams. The scenario instead requires training that addresses mistakes and accidental actions that can create security incidents, which is why Unintentional behavior awareness is the better answer; this option serves the different function defined above.
Answer C is incorrect because Phishing simulation campaign refers to authorized simulated phishing used to measure and improve user recognition and reporting behavior. The scenario instead requires training that addresses mistakes and accidental actions that can create security incidents, which is why Unintentional behavior awareness is the better answer; this option serves the different function defined above.
Answer D is incorrect because Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances. The key mismatch is functional: Unintentional behavior awareness addresses training that addresses mistakes and accidental actions that can create security incidents, the need stated by the question.
Question 17
Which term describes ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies?
- Unexpected behavior recognition
- Recurring awareness training
- Phishing recognition
- Risky behavior recognition
Correct Answer: C
Correct Answer
Answer C is correct because Phishing recognition means ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. This is the precise fit for the scenario. Risky behavior recognition serves the different purpose of awareness of actions that materially increase security exposure.
Incorrect Answers
Answer A is incorrect because Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue. The scenario instead requires ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies, which is why Phishing recognition is the better answer; this option serves the different function defined above.
Answer B is incorrect because Recurring awareness training refers to security education repeated periodically and updated for changing threats and policies. The concept is valid, but it does not match this stem. The required function is ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies, which maps to Phishing recognition.
Answer D is incorrect because Risky behavior recognition refers to awareness of actions that materially increase security exposure. The scenario instead requires ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies, which is why Phishing recognition is the better answer; this option serves the different function defined above.
Question 18
Which term describes guidance on unique credentials, password managers, MFA, and safe credential handling?
- Removable-media training
- Phishing recognition
- Recurring awareness training
- Password-management training
Correct Answer: D
Correct Answer
Answer D is correct because Password-management training means guidance on unique credentials, password managers, MFA, and safe credential handling. That is the function the question is testing. Recurring awareness training would instead be used for security education repeated periodically and updated for changing threats and policies.
Incorrect Answers
Answer A is incorrect because Removable-media training refers to guidance on safe handling of USB drives and other portable media. The scenario instead requires guidance on unique credentials, password managers, MFA, and safe credential handling, which is why Password-management training is the better answer; this option serves the different function defined above.
Answer B is incorrect because Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. This could be appropriate elsewhere, but the required function is guidance on unique credentials, password managers, MFA, and safe credential handling; that makes Password-management training the precise choice.
Answer C is incorrect because Recurring awareness training refers to security education repeated periodically and updated for changing threats and policies. The scenario instead requires guidance on unique credentials, password managers, MFA, and safe credential handling, which is why Password-management training is the better answer; this option serves the different function defined above.
Question 19
A review during a security-awareness program review identifies two gaps. One requires training that helps users recognize security context and adjust behavior to changing circumstances. The other requires security education repeated periodically and updated for changing threats and policies. Which TWO options should be included in the remediation plan? Choose TWO.
- Insider-threat awareness
- Recurring awareness training
- Social-engineering training
- Situational awareness training
- Suspicious-message reporting
Correct Answers: B, D
Correct Answers
Answer B is correct because Recurring awareness training means security education repeated periodically and updated for changing threats and policies. This selection maps directly to one of the named needs. Social-engineering training addresses education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure, so it does not satisfy the same slot.
Answer D is correct because Situational awareness training means training that helps users recognize security context and adjust behavior to changing circumstances. It belongs in the fixed-count answer set because it covers one of the stated requirements. Insider-threat awareness instead serves education on indicators and reporting related to malicious or negligent trusted users and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Insider-threat awareness means education on indicators and reporting related to malicious or negligent trusted users. The fixed-count answer set is Recurring awareness training, Situational awareness training; this option does not fill one of those named functions.
Answer C is incorrect because Social-engineering training means education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. The question requires exactly 2 selections: Recurring awareness training, Situational awareness training. This option falls outside that required set.
Answer E is incorrect because Suspicious-message reporting means a defined method for users to submit potentially malicious messages to security teams. The fixed-count answer set is Recurring awareness training, Situational awareness training; this option does not fill one of those named functions.
Question 20
Which term describes training that helps users recognize security context and adjust behavior to changing circumstances?
- Phishing simulation campaign
- Situational awareness training
- Policy and handbook training
- Remote-work security training
Correct Answer: B
Correct Answer
Answer B is correct because Situational awareness training means training that helps users recognize security context and adjust behavior to changing circumstances. That makes it the best answer here; Phishing simulation campaign addresses authorized simulated phishing used to measure and improve user recognition and reporting behavior, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Phishing simulation campaign refers to authorized simulated phishing used to measure and improve user recognition and reporting behavior. That concept can be valid in another scenario, but this question is testing training that helps users recognize security context and adjust behavior to changing circumstances; Situational awareness training therefore fits the requirement more directly.
Answer C is incorrect because Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior. The question is not asking for this function. It is testing training that helps users recognize security context and adjust behavior to changing circumstances, so Situational awareness training is the stronger fit.
Answer D is incorrect because Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices. That concept can be valid in another scenario, but this question is testing training that helps users recognize security context and adjust behavior to changing circumstances; Situational awareness training therefore fits the requirement more directly.