nerdexam
EC-Council

712-50 · Question #126

The effectiveness of social engineering penetration testing using phishing can be used as a Key Performance Indicator (KPI) for the effectiveness of an organization's

The correct answer is C. Security Awareness Program. Phishing simulations directly test whether employees recognize and resist social engineering attacks - which is the core objective of a Security Awareness Program (C). When staff click phishing links or divulge credentials, it reveals gaps in their training and awareness…

Security Program Management & Operations

Question

The effectiveness of social engineering penetration testing using phishing can be used as a Key Performance Indicator (KPI) for the effectiveness of an organization's

Options

  • ARisk Management Program.
  • BAnti-Spam controls.
  • CSecurity Awareness Program.
  • DIdentity and Access Management Program.

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    78% (18)
  • D
    13% (3)

Explanation

Phishing simulations directly test whether employees recognize and resist social engineering attacks - which is the core objective of a Security Awareness Program (C). When staff click phishing links or divulge credentials, it reveals gaps in their training and awareness, making click-through rates and reporting rates ideal KPIs for that program's effectiveness.

Why the distractors are wrong:

  • A (Risk Management): Risk management is a broad governance framework covering asset, threat, and control analysis - phishing test results are one small input, not a meaningful top-level KPI for the whole program.
  • B (Anti-Spam): Anti-spam controls are technical filters (email gateways, blocklists). Phishing simulations typically bypass these intentionally to test the human layer, so they measure human response, not filter performance.
  • D (Identity and Access Management): IAM governs authentication, authorization, and provisioning - it's about who can access what, not whether users can spot a deceptive email.

Memory tip: Think "phishing tests the person, not the product." Technical controls (spam filters, IAM) protect systems; a Security Awareness Program trains people - so the metric lives with the program that targets human behavior.

Topics

#Social Engineering Testing#Phishing Awareness#Security KPIs#Employee Training

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice