Topic 28 Practice Test 2 covers Security Awareness Practices for CompTIA Security+ SY0-701 and maps to objective 5.6: Given a scenario, implement security awareness practices. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
During a security-awareness program review, three requirements must be addressed: (1) authorized simulated phishing used to measure and improve user recognition and reporting behavior; (2) guidance on unique credentials, password managers, MFA, and safe credential handling; and (3) guidance on protecting devices, networks, conversations, and data outside controlled offices. Which THREE choices best satisfy them? Choose THREE.
- Password-management training
- Insider-threat awareness
- Remote-work security training
- Phishing simulation campaign
- Situational awareness training
- Social-engineering training
Correct Answers: A, C, D
Correct Answers
Answer A is correct because Password-management training means guidance on unique credentials, password managers, MFA, and safe credential handling. The fixed-count item needs this function in the answer set. Insider-threat awareness covers education on indicators and reporting related to malicious or negligent trusted users, a different requirement.
Answer C is correct because Remote-work security training means guidance on protecting devices, networks, conversations, and data outside controlled offices. It belongs in the fixed-count answer set because it covers one of the stated requirements. Insider-threat awareness instead serves education on indicators and reporting related to malicious or negligent trusted users and cannot replace this function.
Answer D is correct because Phishing simulation campaign means authorized simulated phishing used to measure and improve user recognition and reporting behavior. One required function is exactly what this option provides. Situational awareness training may be useful elsewhere, but it is used for training that helps users recognize security context and adjust behavior to changing circumstances.
Incorrect Answers
Answer B is incorrect because Insider-threat awareness means education on indicators and reporting related to malicious or negligent trusted users. The scenario calls for Phishing simulation campaign, Remote-work security training, Password-management training. Selecting this option would leave one of those required functions uncovered.
Answer E is incorrect because Situational awareness training means training that helps users recognize security context and adjust behavior to changing circumstances. The scenario calls for Phishing simulation campaign, Remote-work security training, Password-management training. Selecting this option would leave one of those required functions uncovered.
Answer F is incorrect because Social-engineering training means education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. The question requires exactly 3 selections: Phishing simulation campaign, Remote-work security training, Password-management training. This option falls outside that required set.
Question 2
A design decision in a security-awareness program review must provide security education repeated periodically and updated for changing threats and policies. Which choice most directly satisfies that requirement?
- Suspicious-message reporting
- Risky behavior recognition
- Phishing recognition
- Recurring awareness training
Correct Answer: D
Correct Answer
Answer D is correct because Recurring awareness training means security education repeated periodically and updated for changing threats and policies. This matches the requirement as written. Risky behavior recognition can be valid in another context, but it is used for awareness of actions that materially increase security exposure.
Incorrect Answers
Answer A is incorrect because Suspicious-message reporting means a defined method for users to submit potentially malicious messages to security teams. The question is not asking for this function. It is testing security education repeated periodically and updated for changing threats and policies, so Recurring awareness training is the stronger fit.
Answer B is incorrect because Risky behavior recognition means awareness of actions that materially increase security exposure. This could be appropriate elsewhere, but the required function is security education repeated periodically and updated for changing threats and policies; that makes Recurring awareness training the precise choice.
Answer C is incorrect because Phishing recognition means ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. The concept is valid, but it does not match this stem. The required function is security education repeated periodically and updated for changing threats and policies, which maps to Recurring awareness training.
Question 3
To train users and generate measurable awareness data, which security approach should be selected?
- Phishing simulation campaign
- Password-management training
- Remote-work security training
- Situational awareness training
Correct Answer: A
Correct Answer
Answer A is correct because Phishing simulation campaign means authorized simulated phishing used to measure and improve user recognition and reporting behavior. This is the precise fit for the scenario. Situational awareness training serves the different purpose of training that helps users recognize security context and adjust behavior to changing circumstances.
Incorrect Answers
Answer B is incorrect because Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling. The scenario instead requires authorized simulated phishing used to measure and improve user recognition and reporting behavior, which is why Phishing simulation campaign is the better answer; this option serves the different function defined above.
Answer C is incorrect because Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices. The key mismatch is functional: Phishing simulation campaign addresses authorized simulated phishing used to measure and improve user recognition and reporting behavior, the need stated by the question.
Answer D is incorrect because Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances. The scenario instead requires authorized simulated phishing used to measure and improve user recognition and reporting behavior, which is why Phishing simulation campaign is the better answer; this option serves the different function defined above.
Question 4
What is a defined method for users to submit potentially malicious messages to security teams?
- Suspicious-message reporting
- Recurring awareness training
- Policy and handbook training
- Phishing recognition
Correct Answer: A
Correct Answer
Answer A is correct because Suspicious-message reporting means a defined method for users to submit potentially malicious messages to security teams. This matches the requirement as written. Phishing recognition can be valid in another context, but it is used for ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.
Incorrect Answers
Answer B is incorrect because Recurring awareness training refers to security education repeated periodically and updated for changing threats and policies. The question is not asking for this function. It is testing a defined method for users to submit potentially malicious messages to security teams, so Suspicious-message reporting is the stronger fit.
Answer C is incorrect because Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior. The scenario instead requires a defined method for users to submit potentially malicious messages to security teams, which is why Suspicious-message reporting is the better answer; this option serves the different function defined above.
Answer D is incorrect because Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. That concept can be valid in another scenario, but this question is testing a defined method for users to submit potentially malicious messages to security teams; Suspicious-message reporting therefore fits the requirement more directly.
Question 5
To encourage early reporting of anomalies rather than ignoring them, which security approach should be selected?
- Remote-work security training
- Risky behavior recognition
- Unexpected behavior recognition
- Phishing recognition
Correct Answer: C
Correct Answer
Answer C is correct because Unexpected behavior recognition means awareness that unusual system, message, or identity behavior may indicate a security issue. That makes it the best answer here; Phishing recognition addresses ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices. The concept is valid, but it does not match this stem. The required function is awareness that unusual system, message, or identity behavior may indicate a security issue, which maps to Unexpected behavior recognition.
Answer B is incorrect because Risky behavior recognition refers to awareness of actions that materially increase security exposure. That concept can be valid in another scenario, but this question is testing awareness that unusual system, message, or identity behavior may indicate a security issue; Unexpected behavior recognition therefore fits the requirement more directly.
Answer D is incorrect because Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. This could be appropriate elsewhere, but the required function is awareness that unusual system, message, or identity behavior may indicate a security issue; that makes Unexpected behavior recognition the precise choice.
Question 6
To turn employees into an early detection source and support rapid analysis, which security approach should be selected?
- Removable-media training
- Unintentional behavior awareness
- Unexpected behavior recognition
- Suspicious-message reporting
Correct Answer: D
Correct Answer
Answer D is correct because Suspicious-message reporting means a defined method for users to submit potentially malicious messages to security teams. The deciding point is functional fit: this option covers the stated need, while Unexpected behavior recognition addresses awareness that unusual system, message, or identity behavior may indicate a security issue.
Incorrect Answers
Answer A is incorrect because Removable-media training refers to guidance on safe handling of USB drives and other portable media. The key mismatch is functional: Suspicious-message reporting addresses a defined method for users to submit potentially malicious messages to security teams, the need stated by the question.
Answer B is incorrect because Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents. This could be appropriate elsewhere, but the required function is a defined method for users to submit potentially malicious messages to security teams; that makes Suspicious-message reporting the precise choice.
Answer C is incorrect because Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue. The key mismatch is functional: Suspicious-message reporting addresses a defined method for users to submit potentially malicious messages to security teams, the need stated by the question.
Question 7
A security engineer is working through a security-awareness program review. The immediate requirement is education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. Which choice is the best fit?
- Operational security awareness
- Social-engineering training
- Unintentional behavior awareness
- Suspicious-message reporting
Correct Answer: B
Correct Answer
Answer B is correct because Social-engineering training means education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. That is the function the question is testing. Suspicious-message reporting would instead be used for a defined method for users to submit potentially malicious messages to security teams.
Incorrect Answers
Answer A is incorrect because Operational security awareness means training on avoiding unnecessary exposure of sensitive operational details. That concept can be valid in another scenario, but this question is testing education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure; Social-engineering training therefore fits the requirement more directly.
Answer C is incorrect because Unintentional behavior awareness means training that addresses mistakes and accidental actions that can create security incidents. The concept is valid, but it does not match this stem. The required function is education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure, which maps to Social-engineering training.
Answer D is incorrect because Suspicious-message reporting means a defined method for users to submit potentially malicious messages to security teams. That concept can be valid in another scenario, but this question is testing education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure; Social-engineering training therefore fits the requirement more directly.
Question 8
An architect working on a security-awareness program review needs one capability that provides defined method for users to submit potentially malicious messages to security teams and another that provides guidance on safe handling of USB drives and other portable media. Which TWO selections are the best match? Choose TWO.
- Unintentional behavior awareness
- Suspicious-message reporting
- Removable-media training
- Policy and handbook training
- Recurring awareness training
Correct Answers: B, C
Correct Answers
Answer B is correct because Suspicious-message reporting means a defined method for users to submit potentially malicious messages to security teams. This option satisfies a specific requirement in the stem; Unintentional behavior awareness serves training that addresses mistakes and accidental actions that can create security incidents and therefore is not interchangeable with it.
Answer C is correct because Removable-media training means guidance on safe handling of USB drives and other portable media. It belongs in the fixed-count answer set because it covers one of the stated requirements. Policy and handbook training instead serves education on organizational rules, responsibilities, and expected security behavior and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Unintentional behavior awareness means training that addresses mistakes and accidental actions that can create security incidents. The required choices are Suspicious-message reporting, Removable-media training. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer D is incorrect because Policy and handbook training means education on organizational rules, responsibilities, and expected security behavior. The scenario calls for Suspicious-message reporting, Removable-media training. Selecting this option would leave one of those required functions uncovered. For example, Removable-media training is required for guidance on safe handling of USB drives and other portable media.
Answer E is incorrect because Recurring awareness training means security education repeated periodically and updated for changing threats and policies. The question requires exactly 2 selections: Suspicious-message reporting, Removable-media training. This option falls outside that required set. For example, Removable-media training is required for guidance on safe handling of USB drives and other portable media.
Question 9
During a security-awareness program review, the team has two independent requirements: (1) defined method for users to submit potentially malicious messages to security teams; and (2) guidance on unique credentials, password managers, MFA, and safe credential handling. Which TWO choices best satisfy those requirements? Choose TWO.
- Password-management training
- Unintentional behavior awareness
- Suspicious-message reporting
- Remote-work security training
- Operational security awareness
Correct Answers: A, C
Correct Answers
Answer A is correct because Password-management training means guidance on unique credentials, password managers, MFA, and safe credential handling. It belongs in the fixed-count answer set because it covers one of the stated requirements. Unintentional behavior awareness instead serves training that addresses mistakes and accidental actions that can create security incidents and cannot replace this function.
Answer C is correct because Suspicious-message reporting means a defined method for users to submit potentially malicious messages to security teams. It belongs in the fixed-count answer set because it covers one of the stated requirements. Remote-work security training instead serves guidance on protecting devices, networks, conversations, and data outside controlled offices and cannot replace this function.
Incorrect Answers
Answer B is incorrect because Unintentional behavior awareness means training that addresses mistakes and accidental actions that can create security incidents. The question requires exactly 2 selections: Suspicious-message reporting, Password-management training. This option falls outside that required set. For example, Password-management training is required for guidance on unique credentials, password managers, MFA, and safe credential handling.
Answer D is incorrect because Remote-work security training means guidance on protecting devices, networks, conversations, and data outside controlled offices. The scenario calls for Suspicious-message reporting, Password-management training. Selecting this option would leave one of those required functions uncovered.
Answer E is incorrect because Operational security awareness means training on avoiding unnecessary exposure of sensitive operational details. The required choices are Suspicious-message reporting, Password-management training. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 10
To ensure users understand mandatory procedures and acceptable use, which security approach should be selected?
- Risky behavior recognition
- Phishing recognition
- Unexpected behavior recognition
- Policy and handbook training
Correct Answer: D
Correct Answer
Answer D is correct because Policy and handbook training means education on organizational rules, responsibilities, and expected security behavior. The deciding point is functional fit: this option covers the stated need, while Phishing recognition addresses ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.
Incorrect Answers
Answer A is incorrect because Risky behavior recognition refers to awareness of actions that materially increase security exposure. The key mismatch is functional: Policy and handbook training addresses education on organizational rules, responsibilities, and expected security behavior, the need stated by the question.
Answer B is incorrect because Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. The scenario instead requires education on organizational rules, responsibilities, and expected security behavior, which is why Policy and handbook training is the better answer; this option serves the different function defined above.
Answer C is incorrect because Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue. The question is not asking for this function. It is testing education on organizational rules, responsibilities, and expected security behavior, so Policy and handbook training is the stronger fit.
Question 11
Which term describes education on organizational rules, responsibilities, and expected security behavior?
- Unintentional behavior awareness
- Removable-media training
- Policy and handbook training
- Operational security awareness
Correct Answer: C
Correct Answer
Answer C is correct because Policy and handbook training means education on organizational rules, responsibilities, and expected security behavior. That is the function the question is testing. Removable-media training would instead be used for guidance on safe handling of USB drives and other portable media.
Incorrect Answers
Answer A is incorrect because Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents. This could be appropriate elsewhere, but the required function is education on organizational rules, responsibilities, and expected security behavior; that makes Policy and handbook training the precise choice.
Answer B is incorrect because Removable-media training refers to guidance on safe handling of USB drives and other portable media. The scenario instead requires education on organizational rules, responsibilities, and expected security behavior, which is why Policy and handbook training is the better answer; this option serves the different function defined above.
Answer D is incorrect because Operational security awareness refers to training on avoiding unnecessary exposure of sensitive operational details. This could be appropriate elsewhere, but the required function is education on organizational rules, responsibilities, and expected security behavior; that makes Policy and handbook training the precise choice.
Question 12
During a security-awareness program review, the team needs awareness of actions that materially increase security exposure. Which option best meets this requirement?
- Unexpected behavior recognition
- Phishing simulation campaign
- Risky behavior recognition
- Policy and handbook training
Correct Answer: C
Correct Answer
Answer C is correct because Risky behavior recognition means awareness of actions that materially increase security exposure. That makes it the best answer here; Unexpected behavior recognition addresses awareness that unusual system, message, or identity behavior may indicate a security issue, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Unexpected behavior recognition means awareness that unusual system, message, or identity behavior may indicate a security issue. That concept can be valid in another scenario, but this question is testing awareness of actions that materially increase security exposure; Risky behavior recognition therefore fits the requirement more directly.
Answer B is incorrect because Phishing simulation campaign means authorized simulated phishing used to measure and improve user recognition and reporting behavior. That concept can be valid in another scenario, but this question is testing awareness of actions that materially increase security exposure; Risky behavior recognition therefore fits the requirement more directly.
Answer D is incorrect because Policy and handbook training means education on organizational rules, responsibilities, and expected security behavior. The concept is valid, but it does not match this stem. The required function is awareness of actions that materially increase security exposure, which maps to Risky behavior recognition.
Question 13
A review during a security-awareness program review identifies two gaps. One requires education on indicators and reporting related to malicious or negligent trusted users. The other requires education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. Which TWO options should be included in the remediation plan? Choose TWO.
- Risky behavior recognition
- Insider-threat awareness
- Social-engineering training
- Removable-media training
- Phishing recognition
Correct Answers: B, C
Correct Answers
Answer B is correct because Insider-threat awareness means education on indicators and reporting related to malicious or negligent trusted users. This selection maps directly to one of the named needs. Phishing recognition addresses ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies, so it does not satisfy the same slot.
Answer C is correct because Social-engineering training means education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. This selection maps directly to one of the named needs. Removable-media training addresses guidance on safe handling of USB drives and other portable media, so it does not satisfy the same slot.
Incorrect Answers
Answer A is incorrect because Risky behavior recognition means awareness of actions that materially increase security exposure. The fixed-count answer set is Insider-threat awareness, Social-engineering training; this option does not fill one of those named functions. For example, Insider-threat awareness is required for education on indicators and reporting related to malicious or negligent trusted users.
Answer D is incorrect because Removable-media training means guidance on safe handling of USB drives and other portable media. The fixed-count answer set is Insider-threat awareness, Social-engineering training; this option does not fill one of those named functions. For example, Social-engineering training is required for education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure.
Answer E is incorrect because Phishing recognition means ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. Every answer slot must map to a stated requirement. The correct set is Insider-threat awareness, Social-engineering training, so this option cannot replace one of those selections.
Question 14
Which term describes training on avoiding unnecessary exposure of sensitive operational details?
- Situational awareness training
- Policy and handbook training
- Social-engineering training
- Operational security awareness
Correct Answer: D
Correct Answer
Answer D is correct because Operational security awareness means training on avoiding unnecessary exposure of sensitive operational details. The deciding point is functional fit: this option covers the stated need, while Situational awareness training addresses training that helps users recognize security context and adjust behavior to changing circumstances.
Incorrect Answers
Answer A is incorrect because Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances. The key mismatch is functional: Operational security awareness addresses training on avoiding unnecessary exposure of sensitive operational details, the need stated by the question.
Answer B is incorrect because Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior. This could be appropriate elsewhere, but the required function is training on avoiding unnecessary exposure of sensitive operational details; that makes Operational security awareness the precise choice.
Answer C is incorrect because Social-engineering training refers to education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. The key mismatch is functional: Operational security awareness addresses training on avoiding unnecessary exposure of sensitive operational details, the need stated by the question.
Question 15
Which term describes awareness that unusual system, message, or identity behavior may indicate a security issue?
- Situational awareness training
- Unexpected behavior recognition
- Operational security awareness
- Insider-threat awareness
Correct Answer: B
Correct Answer
Answer B is correct because Unexpected behavior recognition means awareness that unusual system, message, or identity behavior may indicate a security issue. This is the precise fit for the scenario. Operational security awareness serves the different purpose of training on avoiding unnecessary exposure of sensitive operational details.
Incorrect Answers
Answer A is incorrect because Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances. The concept is valid, but it does not match this stem. The required function is awareness that unusual system, message, or identity behavior may indicate a security issue, which maps to Unexpected behavior recognition.
Answer C is incorrect because Operational security awareness refers to training on avoiding unnecessary exposure of sensitive operational details. The concept is valid, but it does not match this stem. The required function is awareness that unusual system, message, or identity behavior may indicate a security issue, which maps to Unexpected behavior recognition.
Answer D is incorrect because Insider-threat awareness refers to education on indicators and reporting related to malicious or negligent trusted users. The scenario instead requires awareness that unusual system, message, or identity behavior may indicate a security issue, which is why Unexpected behavior recognition is the better answer; this option serves the different function defined above.
Question 16
A review during a security-awareness program review identifies two gaps. One requires awareness of actions that materially increase security exposure. The other requires guidance on unique credentials, password managers, MFA, and safe credential handling. Which TWO options should be included in the remediation plan? Choose TWO.
- Phishing recognition
- Risky behavior recognition
- Password-management training
- Social-engineering training
- Operational security awareness
Correct Answers: B, C
Correct Answers
Answer B is correct because Risky behavior recognition means awareness of actions that materially increase security exposure. It belongs in the fixed-count answer set because it covers one of the stated requirements. Operational security awareness instead serves training on avoiding unnecessary exposure of sensitive operational details and cannot replace this function.
Answer C is correct because Password-management training means guidance on unique credentials, password managers, MFA, and safe credential handling. One required function is exactly what this option provides. Operational security awareness may be useful elsewhere, but it is used for training on avoiding unnecessary exposure of sensitive operational details.
Incorrect Answers
Answer A is incorrect because Phishing recognition means ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. The question requires exactly 2 selections: Risky behavior recognition, Password-management training. This option falls outside that required set. For example, Risky behavior recognition is required for awareness of actions that materially increase security exposure.
Answer D is incorrect because Social-engineering training means education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. The required choices are Risky behavior recognition, Password-management training. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer E is incorrect because Operational security awareness means training on avoiding unnecessary exposure of sensitive operational details. The fixed-count answer set is Risky behavior recognition, Password-management training; this option does not fill one of those named functions. For example, Password-management training is required for guidance on unique credentials, password managers, MFA, and safe credential handling.
Question 17
To reduce successful social-engineering attacks through informed user decisions, which security approach should be selected?
- Suspicious-message reporting
- Situational awareness training
- Phishing recognition
- Risky behavior recognition
Correct Answer: C
Correct Answer
Answer C is correct because Phishing recognition means ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. The deciding point is functional fit: this option covers the stated need, while Situational awareness training addresses training that helps users recognize security context and adjust behavior to changing circumstances.
Incorrect Answers
Answer A is incorrect because Suspicious-message reporting refers to a defined method for users to submit potentially malicious messages to security teams. That concept can be valid in another scenario, but this question is testing ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies; Phishing recognition therefore fits the requirement more directly.
Answer B is incorrect because Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances. That concept can be valid in another scenario, but this question is testing ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies; Phishing recognition therefore fits the requirement more directly.
Answer D is incorrect because Risky behavior recognition refers to awareness of actions that materially increase security exposure. The key mismatch is functional: Phishing recognition addresses ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies, the need stated by the question.
Question 18
A review during a security-awareness program review identifies two gaps. One requires ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. The other requires education on indicators and reporting related to malicious or negligent trusted users. Which TWO options should be included in the remediation plan? Choose TWO.
- Insider-threat awareness
- Social-engineering training
- Phishing recognition
- Recurring awareness training
- Remote-work security training
Correct Answers: A, C
Correct Answers
Answer A is correct because Insider-threat awareness means education on indicators and reporting related to malicious or negligent trusted users. It belongs in the fixed-count answer set because it covers one of the stated requirements. Remote-work security training instead serves guidance on protecting devices, networks, conversations, and data outside controlled offices and cannot replace this function.
Answer C is correct because Phishing recognition means ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. One required function is exactly what this option provides. Social-engineering training may be useful elsewhere, but it is used for education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure.
Incorrect Answers
Answer B is incorrect because Social-engineering training means education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure. The scenario calls for Phishing recognition, Insider-threat awareness. Selecting this option would leave one of those required functions uncovered.
Answer D is incorrect because Recurring awareness training means security education repeated periodically and updated for changing threats and policies. The fixed-count answer set is Phishing recognition, Insider-threat awareness; this option does not fill one of those named functions.
Answer E is incorrect because Remote-work security training means guidance on protecting devices, networks, conversations, and data outside controlled offices. The scenario calls for Phishing recognition, Insider-threat awareness. Selecting this option would leave one of those required functions uncovered.
Question 19
Which term describes guidance on safe handling of USB drives and other portable media?
- Policy and handbook training
- Removable-media training
- Phishing recognition
- Unintentional behavior awareness
Correct Answer: B
Correct Answer
Answer B is correct because Removable-media training means guidance on safe handling of USB drives and other portable media. That is the function the question is testing. Unintentional behavior awareness would instead be used for training that addresses mistakes and accidental actions that can create security incidents.
Incorrect Answers
Answer A is incorrect because Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior. The scenario instead requires guidance on safe handling of USB drives and other portable media, which is why Removable-media training is the better answer; this option serves the different function defined above.
Answer C is incorrect because Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies. This could be appropriate elsewhere, but the required function is guidance on safe handling of USB drives and other portable media; that makes Removable-media training the precise choice.
Answer D is incorrect because Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents. The scenario instead requires guidance on safe handling of USB drives and other portable media, which is why Removable-media training is the better answer; this option serves the different function defined above.
Question 20
Which term describes awareness of actions that materially increase security exposure?
- Risky behavior recognition
- Recurring awareness training
- Removable-media training
- Remote-work security training
Correct Answer: A
Correct Answer
Answer A is correct because Risky behavior recognition means awareness of actions that materially increase security exposure. This is the precise fit for the scenario. Remote-work security training serves the different purpose of guidance on protecting devices, networks, conversations, and data outside controlled offices.
Incorrect Answers
Answer B is incorrect because Recurring awareness training refers to security education repeated periodically and updated for changing threats and policies. The scenario instead requires awareness of actions that materially increase security exposure, which is why Risky behavior recognition is the better answer; this option serves the different function defined above.
Answer C is incorrect because Removable-media training refers to guidance on safe handling of USB drives and other portable media. The question is not asking for this function. It is testing awareness of actions that materially increase security exposure, so Risky behavior recognition is the stronger fit.
Answer D is incorrect because Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices. That concept can be valid in another scenario, but this question is testing awareness of actions that materially increase security exposure; Risky behavior recognition therefore fits the requirement more directly.