CompTIA Security+ SY0-701 Security Awareness Practices Practice Test
Topic 28 focuses on Security Awareness Practices for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
Which term describes authorized simulated phishing used to measure and improve user recognition and reporting behavior?
Correct Answer: A
Correct Answer
Answer A is correct because Phishing simulation campaign means authorized simulated phishing used to measure and improve user recognition and reporting behavior.
Incorrect Answers
Answer B is incorrect because Risky behavior recognition addresses a different requirement. Risky behavior recognition refers to awareness of actions that materially increase security exposure.
Answer C is incorrect because Password-management training represents a different security function. Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling.
Answer D is incorrect because Insider-threat awareness would fit a different scenario. Insider-threat awareness refers to education on indicators and reporting related to malicious or negligent trusted users.
Question 2
To reduce successful social-engineering attacks through informed user decisions, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Phishing recognition means ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.
Incorrect Answers
Answer B is incorrect because Suspicious-message reporting addresses a different requirement. Suspicious-message reporting refers to a defined method for users to submit potentially malicious messages to security teams.
Answer C is incorrect because Situational awareness training would fit a different scenario. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.
Answer D is incorrect because Risky behavior recognition addresses a different security requirement. Risky behavior recognition refers to awareness of actions that materially increase security exposure.
Question 3
What is a defined method for users to submit potentially malicious messages to security teams?
Correct Answer: B
Correct Answer
Answer B is correct because Suspicious-message reporting means a defined method for users to submit potentially malicious messages to security teams.
Incorrect Answers
Answer A is incorrect because Phishing recognition addresses a different requirement. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.
Answer C is incorrect because Recurring awareness training represents a different security function. Recurring awareness training refers to security education repeated periodically and updated for changing threats and policies.
Answer D is incorrect because Policy and handbook training would fit a different scenario. Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior.
Question 4
To help users identify practices that could lead to compromise, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Risky behavior recognition means awareness of actions that materially increase security exposure.
Incorrect Answers
Answer A is incorrect because Situational awareness training addresses a different requirement. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.
Answer B is incorrect because Unexpected behavior recognition addresses a different security requirement. Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue.
Answer C is incorrect because Password-management training would fit a different scenario. Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling.
Question 5
Which term describes awareness that unusual system, message, or identity behavior may indicate a security issue?
Correct Answer: B
Correct Answer
Answer B is correct because Unexpected behavior recognition means awareness that unusual system, message, or identity behavior may indicate a security issue.
Incorrect Answers
Answer A is incorrect because Operational security awareness addresses a different requirement. Operational security awareness refers to training on avoiding unnecessary exposure of sensitive operational details.
Answer C is incorrect because Insider-threat awareness would fit a different scenario. Insider-threat awareness refers to education on indicators and reporting related to malicious or negligent trusted users.
Answer D is incorrect because Situational awareness training represents a different security function. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.
Question 6
To reduce incidents caused by error rather than malicious intent, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Unintentional behavior awareness means training that addresses mistakes and accidental actions that can create security incidents.
Incorrect Answers
Answer A is incorrect because Suspicious-message reporting addresses a different security requirement. Suspicious-message reporting refers to a defined method for users to submit potentially malicious messages to security teams.
Answer B is incorrect because Phishing simulation campaign addresses a different requirement. Phishing simulation campaign refers to authorized simulated phishing used to measure and improve user recognition and reporting behavior.
Answer C is incorrect because Situational awareness training would fit a different scenario. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.
Question 7
Which term describes education on organizational rules, responsibilities, and expected security behavior?
Correct Answer: C
Correct Answer
Answer C is correct because Policy and handbook training means education on organizational rules, responsibilities, and expected security behavior.
Incorrect Answers
Answer A is incorrect because Operational security awareness represents a different security function. Operational security awareness refers to training on avoiding unnecessary exposure of sensitive operational details.
Answer B is incorrect because Removable-media training would fit a different scenario. Removable-media training refers to guidance on safe handling of USB drives and other portable media.
Answer D is incorrect because Unintentional behavior awareness addresses a different requirement. Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents.
Question 8
To improve decisions when working in public, remote, or unusual environments, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Situational awareness training means training that helps users recognize security context and adjust behavior to changing circumstances.
Incorrect Answers
Answer B is incorrect because Social-engineering training addresses a different requirement. Social-engineering training refers to education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure.
Answer C is incorrect because Unintentional behavior awareness would fit a different scenario. Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents.
Answer D is incorrect because Password-management training addresses a different security requirement. Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling.
Question 9
Which term describes education on indicators and reporting related to malicious or negligent trusted users?
Correct Answer: A
Correct Answer
Answer A is correct because Insider-threat awareness means education on indicators and reporting related to malicious or negligent trusted users.
Incorrect Answers
Answer B is incorrect because Unintentional behavior awareness represents a different security function. Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents.
Answer C is incorrect because Social-engineering training would fit a different scenario. Social-engineering training refers to education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure.
Answer D is incorrect because Suspicious-message reporting addresses a different requirement. Suspicious-message reporting refers to a defined method for users to submit potentially malicious messages to security teams.
Question 10
To reduce compromise caused by weak, reused, or mishandled passwords, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Password-management training means guidance on unique credentials, password managers, MFA, and safe credential handling.
Incorrect Answers
Answer B is incorrect because Remote-work security training addresses a different requirement. Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices.
Answer C is incorrect because Situational awareness training addresses a different security requirement. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.
Answer D is incorrect because Removable-media training would fit a different scenario. Removable-media training refers to guidance on safe handling of USB drives and other portable media.
Question 11
Which term describes guidance on safe handling of USB drives and other portable media?
Correct Answer: B
Correct Answer
Answer B is correct because Removable-media training means guidance on safe handling of USB drives and other portable media.
Incorrect Answers
Answer A is incorrect because Phishing recognition would fit a different scenario. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.
Answer C is incorrect because Unintentional behavior awareness addresses a different requirement. Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents.
Answer D is incorrect because Policy and handbook training represents a different security function. Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior.
Question 12
To help users resist nontechnical attacks that target human trust, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Social-engineering training means education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure.
Incorrect Answers
Answer A is incorrect because Unexpected behavior recognition would fit a different scenario. Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue.
Answer B is incorrect because Situational awareness training addresses a different requirement. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.
Answer D is incorrect because Removable-media training addresses a different security requirement. Removable-media training refers to guidance on safe handling of USB drives and other portable media.
Question 13
Which term describes training on avoiding unnecessary exposure of sensitive operational details?
Correct Answer: C
Correct Answer
Answer C is correct because Operational security awareness means training on avoiding unnecessary exposure of sensitive operational details.
Incorrect Answers
Answer A is incorrect because Social-engineering training would fit a different scenario. Social-engineering training refers to education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure.
Answer B is incorrect because Situational awareness training addresses a different requirement. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.
Answer D is incorrect because Policy and handbook training represents a different security function. Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior.
Question 14
To reduce security risk in home, travel, and hybrid work environments, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Remote-work security training means guidance on protecting devices, networks, conversations, and data outside controlled offices.
Incorrect Answers
Answer A is incorrect because Password-management training addresses a different requirement. Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling.
Answer C is incorrect because Phishing simulation campaign would fit a different scenario. Phishing simulation campaign refers to authorized simulated phishing used to measure and improve user recognition and reporting behavior.
Answer D is incorrect because Situational awareness training addresses a different security requirement. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.
Question 15
Which term describes security education repeated periodically and updated for changing threats and policies?
Correct Answer: C
Correct Answer
Answer C is correct because Recurring awareness training means security education repeated periodically and updated for changing threats and policies.
Incorrect Answers
Answer A is incorrect because Phishing recognition would fit a different scenario. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.
Answer B is incorrect because Operational security awareness addresses a different requirement. Operational security awareness refers to training on avoiding unnecessary exposure of sensitive operational details.
Answer D is incorrect because Social-engineering training represents a different security function. Social-engineering training refers to education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure.
Question 16
To train users and generate measurable awareness data, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Phishing simulation campaign means authorized simulated phishing used to measure and improve user recognition and reporting behavior.
Incorrect Answers
Answer A is incorrect because Password-management training would fit a different scenario. Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling.
Answer C is incorrect because Situational awareness training addresses a different requirement. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.
Answer D is incorrect because Remote-work security training represents a different security function. Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices.
Question 17
Which term describes ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies?
Correct Answer: A
Correct Answer
Answer A is correct because Phishing recognition means ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.
Incorrect Answers
Answer B is incorrect because Recurring awareness training addresses a different security requirement. Recurring awareness training refers to security education repeated periodically and updated for changing threats and policies.
Answer C is incorrect because Unexpected behavior recognition addresses a different requirement. Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue.
Answer D is incorrect because Risky behavior recognition would fit a different scenario. Risky behavior recognition refers to awareness of actions that materially increase security exposure.
Question 18
To turn employees into an early detection source and support rapid analysis, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Suspicious-message reporting means a defined method for users to submit potentially malicious messages to security teams.
Incorrect Answers
Answer A is incorrect because Unintentional behavior awareness addresses a different requirement. Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents.
Answer B is incorrect because Unexpected behavior recognition represents a different security function. Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue.
Answer D is incorrect because Removable-media training would fit a different scenario. Removable-media training refers to guidance on safe handling of USB drives and other portable media.
Question 19
Which term describes awareness of actions that materially increase security exposure?
Correct Answer: D
Correct Answer
Answer D is correct because Risky behavior recognition means awareness of actions that materially increase security exposure.
Incorrect Answers
Answer A is incorrect because Removable-media training would fit a different scenario. Removable-media training refers to guidance on safe handling of USB drives and other portable media.
Answer B is incorrect because Recurring awareness training addresses a different requirement. Recurring awareness training refers to security education repeated periodically and updated for changing threats and policies.
Answer C is incorrect because Remote-work security training addresses a different security requirement. Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices.
Question 20
To encourage early reporting of anomalies rather than ignoring them, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Unexpected behavior recognition means awareness that unusual system, message, or identity behavior may indicate a security issue.
Incorrect Answers
Answer B is incorrect because Phishing recognition would fit a different scenario. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.
Answer C is incorrect because Remote-work security training represents a different security function. Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices.
Answer D is incorrect because Risky behavior recognition addresses a different requirement. Risky behavior recognition refers to awareness of actions that materially increase security exposure.
Question 21
Which term describes training that addresses mistakes and accidental actions that can create security incidents?
Correct Answer: B
Correct Answer
Answer B is correct because Unintentional behavior awareness means training that addresses mistakes and accidental actions that can create security incidents.
Incorrect Answers
Answer A is incorrect because Policy and handbook training addresses a different security requirement. Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior.
Answer C is incorrect because Phishing simulation campaign addresses a different requirement. Phishing simulation campaign refers to authorized simulated phishing used to measure and improve user recognition and reporting behavior.
Answer D is incorrect because Phishing recognition would fit a different scenario. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.
Question 22
To ensure users understand mandatory procedures and acceptable use, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Policy and handbook training means education on organizational rules, responsibilities, and expected security behavior.
Incorrect Answers
Answer A is incorrect because Risky behavior recognition represents a different security function. Risky behavior recognition refers to awareness of actions that materially increase security exposure.
Answer B is incorrect because Phishing recognition addresses a different requirement. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.
Answer C is incorrect because Unexpected behavior recognition would fit a different scenario. Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue.
Question 23
Which term describes training that helps users recognize security context and adjust behavior to changing circumstances?
Correct Answer: C
Correct Answer
Answer C is correct because Situational awareness training means training that helps users recognize security context and adjust behavior to changing circumstances.
Incorrect Answers
Answer A is incorrect because Policy and handbook training addresses a different security requirement. Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior.
Answer B is incorrect because Remote-work security training addresses a different requirement. Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices.
Answer D is incorrect because Phishing simulation campaign would fit a different scenario. Phishing simulation campaign refers to authorized simulated phishing used to measure and improve user recognition and reporting behavior.
Question 24
To help employees identify concerning behavior without encouraging unsupported accusations, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Insider-threat awareness means education on indicators and reporting related to malicious or negligent trusted users.
Incorrect Answers
Answer A is incorrect because Unintentional behavior awareness represents a different security function. Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents.
Answer B is incorrect because Risky behavior recognition would fit a different scenario. Risky behavior recognition refers to awareness of actions that materially increase security exposure.
Answer C is incorrect because Password-management training addresses a different requirement. Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling.
Question 25
Which term describes guidance on unique credentials, password managers, MFA, and safe credential handling?
Correct Answer: D
Correct Answer
Answer D is correct because Password-management training means guidance on unique credentials, password managers, MFA, and safe credential handling.
Incorrect Answers
Answer A is incorrect because Recurring awareness training addresses a different requirement. Recurring awareness training refers to security education repeated periodically and updated for changing threats and policies.
Answer B is incorrect because Removable-media training addresses a different security requirement. Removable-media training refers to guidance on safe handling of USB drives and other portable media.
Answer C is incorrect because Phishing recognition would fit a different scenario. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.
Popular posts
Recent Posts
