exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 576 discussion

Actual exam question from CompTIA's SY0-701
Question #: 576
Topic #: 1
[All SY0-701 Questions]

A company is concerned about employees unintentionally introducing malware into the network. The company identified fifty employees who clicked on a link embedded in an email sent by the internal IT department. Which of the following should the company implement to best improve its security posture?

  • A. Social engineering training
  • B. SPF configuration
  • C. Simulated phishing campaign
  • D. Insider threat awareness
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Nahidwin
Highly Voted 1 month, 3 weeks ago
Selected Answer: A
(A) IT department already conducted a phishing camping , Social engineering would be best to improve security posture
upvoted 5 times
...
Turrtle
Most Recent 1 month, 3 weeks ago
Selected Answer: C
Training is important, but passive education alone may not be as effective as hands-on simulations.
upvoted 1 times
Konversation
2 weeks, 6 days ago
"...an email sent by the internal IT department". It was an simulated phishing campaign.
upvoted 1 times
...
...
e157c7c
1 month, 4 weeks ago
Selected Answer: B
SPF Configuration. Sender Policy Framework is used to protect the email system from Phishing and Spoofing. This wouldn't be A because it doesn't address the stated concern of unintentional malware. This wouldn't be C because they JUST DID a simulated phishing campaign. This wouldn't be D because it also doesn't really address the stated concern of unintentional malware.
upvoted 1 times
...
b6133b6
2 months ago
Selected Answer: A
since they already failed phishing campaigns, social engineering training should be carried out.
upvoted 3 times
...
test_arrow
2 months ago
Selected Answer: C
A simulated phishing campaign is a security exercise in which a company sends fake phishing emails to employees to test their ability to recognize and avoid phishing attacks. In this case, 50 employees clicked on a phishing link, which indicates a potential security risk. By implementing a simulated phishing campaign: Identifies Vulnerable Employees – The company can track which employees fall for phishing attempts and need additional training. Raises Awareness – Employees experience a realistic phishing scenario and learn from their mistakes without real consequences. Measures Security Posture – The company can evaluate how often employees are clicking on malicious links and adjust security policies accordingly. Reinforces Training – Employees who fail the phishing test can be redirected to security awareness training, improving their ability to spot real threats. Reduces Future Risk – Regular phishing simulations help employees develop better security habits, reducing the likelihood of falling for real phishing attacks.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago