5.6 Given a scenario, implement security awareness practices
Domain 5: Security Program Management and Oversight
Security awareness is the human-layer objective: implementing programs that change user behavior, not just delivering training. Phishing content dominates — running phishing simulation campaigns, teaching users to recognize suspicious messages, and building reporting channels so employees escalate what they catch. Know how to spot anomalous behavior categorized as risky, unexpected, or unintentional, and how user guidance covers policies and handbooks, situational awareness, insider threat indicators, password management, removable media and cable risks, social engineering, operational security, and the specific exposure of hybrid and remote work environments. Program questions test execution and monitoring: development of the program, initial and recurring training, and measuring effectiveness so the program improves over time. Scenario items often describe an employee behavior and ask for the appropriate response — usually targeted retraining and process improvement rather than immediate punishment. Candidates frequently treat awareness as a one-time onboarding event; the exam rewards continuous, measured programs where simulation results feed back into training. Remember that a rising phishing report rate is a success signal, not a failure.
What you must know
- phishing simulation campaigns
- recognizing anomalous behavior
- insider threat indicators
- remote work security guidance
- recurring training and measurement
- reporting culture
common pitfall · Candidates treat awareness training as a one-time event and pick punitive responses to failed phishing tests instead of continuous training with measured improvement.
Try a sample question
After a simulated phishing campaign, 22 percent of employees clicked the link and only 3 percent reported the message. The security team wants to lower the click rate and raise the reporting rate before the next quarterly campaign. Which TWO actions best support these goals? (Select TWO.)
- A Publish the names of employees who clicked so peers can hold them accountable.
- B Enroll employees who clicked in short, targeted remedial training on phishing indicators.
- C Configure the email gateway to strip all hyperlinks from inbound external mail.
- D Suspend the accounts of employees who clicked until they pass a security exam.
- E Deploy a one-click report-phishing button in the mail client and recognize employees who use it.
Show answer & explanations
- A Publicly naming employees who failed the simulation discourages honesty and engagement; embarrassed users are more likely to hide future mistakes, which reduces incident visibility and damages security culture.
- B correct ·Correct. Short, targeted remedial training delivered soon after a failed simulation reinforces phishing indicators at a teachable moment and is proven to reduce click rates in subsequent campaigns.
- C Stripping every hyperlink is a heavy-handed technical control that breaks legitimate business email; it does nothing to build the recognition and reporting skills an awareness program develops.
- D Suspending accounts is punitive; it interrupts business operations and teaches employees to conceal mistakes instead of encouraging the recognition and reporting behaviors the team wants to grow.
- E correct ·Correct. A one-click report button removes friction from reporting, and positive recognition rewards the behavior, directly increasing the low 3 percent reporting rate the team wants improved.
sample item — the full bank runs 450+ questions at exam difficulty
Is objective 5.6 your weak spot?
The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.
Check my readiness — free