712-50 · Question #126
The effectiveness of social engineering penetration testing using phishing can be used as a Key Performance Indicator (KPI) for the effectiveness of an organization's
The correct answer is C. Security Awareness Program. Phishing simulations directly test whether employees recognize and resist social engineering attacks - which is the core objective of a Security Awareness Program (C). When staff click phishing links or divulge credentials, it reveals gaps in their training and awareness…
Question
The effectiveness of social engineering penetration testing using phishing can be used as a Key Performance Indicator (KPI) for the effectiveness of an organization's
Options
- ARisk Management Program.
- BAnti-Spam controls.
- CSecurity Awareness Program.
- DIdentity and Access Management Program.
How the community answered
(23 responses)- A4% (1)
- B4% (1)
- C78% (18)
- D13% (3)
Explanation
Phishing simulations directly test whether employees recognize and resist social engineering attacks - which is the core objective of a Security Awareness Program (C). When staff click phishing links or divulge credentials, it reveals gaps in their training and awareness, making click-through rates and reporting rates ideal KPIs for that program's effectiveness.
Why the distractors are wrong:
- A (Risk Management): Risk management is a broad governance framework covering asset, threat, and control analysis - phishing test results are one small input, not a meaningful top-level KPI for the whole program.
- B (Anti-Spam): Anti-spam controls are technical filters (email gateways, blocklists). Phishing simulations typically bypass these intentionally to test the human layer, so they measure human response, not filter performance.
- D (Identity and Access Management): IAM governs authentication, authorization, and provisioning - it's about who can access what, not whether users can spot a deceptive email.
Memory tip: Think "phishing tests the person, not the product." Technical controls (spam filters, IAM) protect systems; a Security Awareness Program trains people - so the metric lives with the program that targets human behavior.
Topics
Community Discussion
No community discussion yet for this question.