nerdexam
CompTIA

SY0-301 · Question #441

Human Resources (HR) would like executives to undergo only two specific security training programs a year. Which of the following provides the BEST level of security training for the executives?…

The correct answer is D. Phishing threats and attacks F. Information security awareness. Executives need high-level security awareness training focused on the threats most relevant to their role and access level. Phishing and general information security awareness are the two most applicable for executive-level personnel.

Security program management and oversight

Question

Human Resources (HR) would like executives to undergo only two specific security training programs a year. Which of the following provides the BEST level of security training for the executives? (Select TWO).

Options

  • AAcceptable use of social media
  • BData handling and disposal
  • CZero day exploits and viruses
  • DPhishing threats and attacks
  • EClean desk and BYOD
  • FInformation security awareness

How the community answered

(46 responses)
  • A
    11% (5)
  • B
    9% (4)
  • C
    2% (1)
  • D
    74% (34)
  • E
    4% (2)

Why each option

Executives need high-level security awareness training focused on the threats most relevant to their role and access level. Phishing and general information security awareness are the two most applicable for executive-level personnel.

AAcceptable use of social media

Acceptable use of social media is too narrow and operational, not a priority security topic for executive-level training.

BData handling and disposal

Data handling and disposal is more relevant for staff who routinely process and manage records, not a top priority for executives.

CZero day exploits and viruses

Zero day exploits and viruses is a highly technical topic better suited for IT/security staff, not executives.

DPhishing threats and attacksCorrect

Phishing threats and attacks is critical for executives because they are prime targets for spear-phishing and business email compromise due to their authority and access to sensitive data.

EClean desk and BYOD

Clean desk and BYOD policies are procedural topics more relevant to general staff, not the most impactful training for executives.

FInformation security awarenessCorrect

Information security awareness is the foundational training for any security program, covering broad policies and responsibilities that are directly applicable to executives regardless of technical depth.

Concept tested: Security awareness training prioritization for executives

Source: https://www.nist.gov/system/files/documents/2017/04/05/nist_sp-800-50.pdf

Topics

#executive security training#phishing awareness#security program#training prioritization

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice