SY0-301 · Question #228
Which of the following is the BEST reason to provide user awareness and training programs for organizational staff?
The correct answer is B. To reduce organizational IT risk. Security awareness and training programs primarily aim to reduce organizational IT risk by educating users to recognize and avoid threats such as phishing, social engineering, and unsafe computing practices. An informed workforce is one of the most effective layers of defense.
Question
Which of the following is the BEST reason to provide user awareness and training programs for organizational staff?
Options
- ATo ensure proper use of social media
- BTo reduce organizational IT risk
- CTo detail business impact analyses
- DTo train staff on zero-days
How the community answered
(45 responses)- B93% (42)
- C4% (2)
- D2% (1)
Why each option
Security awareness and training programs primarily aim to reduce organizational IT risk by educating users to recognize and avoid threats such as phishing, social engineering, and unsafe computing practices. An informed workforce is one of the most effective layers of defense.
Proper use of social media may be one topic covered in awareness training, but it is too narrow a scope to represent the primary and best reason for running an organizational training program.
User awareness training directly reduces organizational IT risk by changing human behavior, which is the most frequently exploited vulnerability in enterprise environments. Educated users are less likely to fall victim to phishing attacks, click malicious links, mishandle sensitive data, or violate security policies, each of which could result in a breach. Security awareness programs transform users from a liability into a proactive layer of defense, addressing the human element that technical controls alone cannot fully mitigate.
Business impact analysis (BIA) is a strategic planning process used to identify critical systems and quantify the effect of disruptions, not a topic delivered to general staff through awareness training.
Zero-day vulnerabilities are unknown exploits with no existing patch or signature, making it impossible to train staff specifically on how to handle threats that have not yet been publicly disclosed.
Concept tested: Purpose of security awareness and training programs
Source: https://csrc.nist.gov/publications/detail/sp/800-50/final
Topics
Community Discussion
No community discussion yet for this question.