nerdexam
CompTIA

CAS-005 · Question #160

A Chief Information Security Officer assigns a team to create malicious communications for a social engineering campaign. The purpose of this campaign is to determine the number of employees who…

The correct answer is A. Phishing. The question describes a social engineering campaign involving malicious communications to test employee susceptibility and asks for training to reduce click rates in the future.

Submitted by fernanda_arg· Mar 6, 2026Governance, Risk, and Compliance

Question

A Chief Information Security Officer assigns a team to create malicious communications for a social engineering campaign. The purpose of this campaign is to determine the number of employees who might be susceptible to social engineering attacks. The following is a summary report from a previous campaign:

Which of the following training modules would reduce click rates in the future?

Options

  • APhishing
  • BWhaling
  • CSmishing
  • DTailgating

How the community answered

(30 responses)
  • A
    93% (28)
  • B
    3% (1)
  • C
    3% (1)

Why each option

The question describes a social engineering campaign involving malicious communications to test employee susceptibility and asks for training to reduce click rates in the future.

APhishingCorrect

Phishing is a type of social engineering attack that attempts to trick individuals into revealing sensitive information, clicking malicious links, or downloading malware, typically via fraudulent emails or messages. Training modules on phishing would directly educate employees on how to identify and avoid such malicious communications, thereby reducing click rates in future campaigns.

BWhaling

Whaling is a specific type of phishing attack targeting high-profile individuals within an organization; while related, a general phishing training module is more broadly applicable to reducing click rates among all employees.

CSmishing

Smishing is phishing conducted via SMS text messages, which is a specific vector, whereas 'malicious communications' typically encompasses email-based attacks that fall under general phishing.

DTailgating

Tailgating is a physical security breach where an unauthorized person follows an authorized person into a restricted area; it is not a digital social engineering attack related to click rates.

Concept tested: Social engineering awareness training

Source: https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/anti-phishing-policies-overview?view=o365-worldwide

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice