nerdexam
EC-Council

712-50 · Question #241

Scenario: Your program is developed around minimizing risk to information by focusing on people, technology, and operations. An effective way to evaluate the effectiveness of an information security…

The correct answer is A. Controlled spear phishing campaigns. Controlled spear phishing campaigns directly test whether end users - including senior executives - can recognize and respond appropriately to targeted social engineering attacks, making them the most realistic and measurable way to evaluate an awareness program's…

Security Program Management & Operations

Question

Scenario: Your program is developed around minimizing risk to information by focusing on people, technology, and operations. An effective way to evaluate the effectiveness of an information security awareness program for end users, especially senior executives, is to conduct periodic:

Options

  • AControlled spear phishing campaigns
  • BPassword changes
  • CBaselining of computer systems
  • DScanning for viruses

How the community answered

(27 responses)
  • A
    85% (23)
  • B
    11% (3)
  • D
    4% (1)

Explanation

Controlled spear phishing campaigns directly test whether end users - including senior executives - can recognize and respond appropriately to targeted social engineering attacks, making them the most realistic and measurable way to evaluate an awareness program's effectiveness. Password changes (B) improve credential hygiene but reveal nothing about whether users can identify threats or have internalized security awareness training. Baselining computer systems (C) is a technical configuration practice that establishes a known-good state for systems, unrelated to measuring human behavior. Scanning for viruses (D) is a reactive technical control that detects malware but does not assess user awareness or decision-making.

Memory tip: Think "test what you train" - since awareness programs focus on human behavior (the "people" pillar), the evaluation method must also target human behavior. Spear phishing campaigns are the only option that directly measures whether training changed how people act, not just system state.

Topics

#Security Awareness#Phishing Simulation#Program Evaluation#User Testing

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice