~/ learn/ comp-400/ cards/ Human factors, awareness and training, and incident response
1 of 4

A simulated phishing message is sent to every member of staff, including those with no IT responsibilities, and the click rate is measured. This programme is best classified as:

A simulated phishing message is sent to every member of staff, including those with no IT responsibilities, and the click rate is measured. This programme is best classified as:

Answer

security awareness

Options - A. security awareness - B. role-based training - C. security education - D. a penetration test of the mail gateway Why - A. Correct — it focuses attention on an issue, reaches every employee, is short and repeated, and is assessed by recognition rather than by skill. - B. Training builds a skill for a role and is assessed by whether the learner can apply it. Everyone receiving it is the tell that this is not role-based. - C. Education builds understanding and insight over a career and is assessed by interpretation. - D. A penetration test attacks the technical controls; this exercise measures human behaviour and does not attempt to defeat the gateway. Awareness focuses attention; training builds a skill; education builds understanding. Audience breadth and assessment method are the two fastest discriminators.

Stallings & Brown 5e ch17 §17.1–17.4; NIST SP 800-50; NIST SP 800-61; ISO/IEC 27002

space flip · ← → navigate · esc to exit
NORMAL ~/memra/library/636906fb-c043-4209-80f0-e03d58306692/flashcard utf-8 LF