SY0-301 · Question #441
Human Resources (HR) would like executives to undergo only two specific security training programs a year. Which of the following provides the BEST level of security training for the executives?…
The correct answer is D. Phishing threats and attacks F. Information security awareness. Executives need high-level security awareness training focused on the threats most relevant to their role and access level. Phishing and general information security awareness are the two most applicable for executive-level personnel.
Question
Human Resources (HR) would like executives to undergo only two specific security training programs a year. Which of the following provides the BEST level of security training for the executives? (Select TWO).
Options
- AAcceptable use of social media
- BData handling and disposal
- CZero day exploits and viruses
- DPhishing threats and attacks
- EClean desk and BYOD
- FInformation security awareness
How the community answered
(46 responses)- A11% (5)
- B9% (4)
- C2% (1)
- D74% (34)
- E4% (2)
Why each option
Executives need high-level security awareness training focused on the threats most relevant to their role and access level. Phishing and general information security awareness are the two most applicable for executive-level personnel.
Acceptable use of social media is too narrow and operational, not a priority security topic for executive-level training.
Data handling and disposal is more relevant for staff who routinely process and manage records, not a top priority for executives.
Zero day exploits and viruses is a highly technical topic better suited for IT/security staff, not executives.
Phishing threats and attacks is critical for executives because they are prime targets for spear-phishing and business email compromise due to their authority and access to sensitive data.
Clean desk and BYOD policies are procedural topics more relevant to general staff, not the most impactful training for executives.
Information security awareness is the foundational training for any security program, covering broad policies and responsibilities that are directly applicable to executives regardless of technical depth.
Concept tested: Security awareness training prioritization for executives
Source: https://www.nist.gov/system/files/documents/2017/04/05/nist_sp-800-50.pdf
Topics
Community Discussion
No community discussion yet for this question.