CompTIA Security+ SY0-701 Security Awareness Practices Practice Test

 

Topic 28 focuses on Security Awareness Practices for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which term describes authorized simulated phishing used to measure and improve user recognition and reporting behavior?

  1. Phishing simulation campaign
  2. Risky behavior recognition
  3. Password-management training
  4. Insider-threat awareness

Correct Answer: A

 

Correct Answer

Answer A is correct because Phishing simulation campaign means authorized simulated phishing used to measure and improve user recognition and reporting behavior.

Incorrect Answers

Answer B is incorrect because Risky behavior recognition addresses a different requirement. Risky behavior recognition refers to awareness of actions that materially increase security exposure.

Answer C is incorrect because Password-management training represents a different security function. Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling.

Answer D is incorrect because Insider-threat awareness would fit a different scenario. Insider-threat awareness refers to education on indicators and reporting related to malicious or negligent trusted users.

 

Question 2

To reduce successful social-engineering attacks through informed user decisions, which security approach should be selected?

  1. Phishing recognition
  2. Suspicious-message reporting
  3. Situational awareness training
  4. Risky behavior recognition

Correct Answer: A

 

Correct Answer

Answer A is correct because Phishing recognition means ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.

Incorrect Answers

Answer B is incorrect because Suspicious-message reporting addresses a different requirement. Suspicious-message reporting refers to a defined method for users to submit potentially malicious messages to security teams.

Answer C is incorrect because Situational awareness training would fit a different scenario. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.

Answer D is incorrect because Risky behavior recognition addresses a different security requirement. Risky behavior recognition refers to awareness of actions that materially increase security exposure.

 

Question 3

What is a defined method for users to submit potentially malicious messages to security teams?

  1. Phishing recognition
  2. Suspicious-message reporting
  3. Recurring awareness training
  4. Policy and handbook training

Correct Answer: B

 

Correct Answer

Answer B is correct because Suspicious-message reporting means a defined method for users to submit potentially malicious messages to security teams.

Incorrect Answers

Answer A is incorrect because Phishing recognition addresses a different requirement. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.

Answer C is incorrect because Recurring awareness training represents a different security function. Recurring awareness training refers to security education repeated periodically and updated for changing threats and policies.

Answer D is incorrect because Policy and handbook training would fit a different scenario. Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior.

 

Question 4

To help users identify practices that could lead to compromise, which security approach should be selected?

  1. Situational awareness training
  2. Unexpected behavior recognition
  3. Password-management training
  4. Risky behavior recognition

Correct Answer: D

 

Correct Answer

Answer D is correct because Risky behavior recognition means awareness of actions that materially increase security exposure.

Incorrect Answers

Answer A is incorrect because Situational awareness training addresses a different requirement. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.

Answer B is incorrect because Unexpected behavior recognition addresses a different security requirement. Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue.

Answer C is incorrect because Password-management training would fit a different scenario. Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling.

 

Question 5

Which term describes awareness that unusual system, message, or identity behavior may indicate a security issue?

  1. Operational security awareness
  2. Unexpected behavior recognition
  3. Insider-threat awareness
  4. Situational awareness training

Correct Answer: B

 

Correct Answer

Answer B is correct because Unexpected behavior recognition means awareness that unusual system, message, or identity behavior may indicate a security issue.

Incorrect Answers

Answer A is incorrect because Operational security awareness addresses a different requirement. Operational security awareness refers to training on avoiding unnecessary exposure of sensitive operational details.

Answer C is incorrect because Insider-threat awareness would fit a different scenario. Insider-threat awareness refers to education on indicators and reporting related to malicious or negligent trusted users.

Answer D is incorrect because Situational awareness training represents a different security function. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.

 

Question 6

To reduce incidents caused by error rather than malicious intent, which security approach should be selected?

  1. Suspicious-message reporting
  2. Phishing simulation campaign
  3. Situational awareness training
  4. Unintentional behavior awareness

Correct Answer: D

 

Correct Answer

Answer D is correct because Unintentional behavior awareness means training that addresses mistakes and accidental actions that can create security incidents.

Incorrect Answers

Answer A is incorrect because Suspicious-message reporting addresses a different security requirement. Suspicious-message reporting refers to a defined method for users to submit potentially malicious messages to security teams.

Answer B is incorrect because Phishing simulation campaign addresses a different requirement. Phishing simulation campaign refers to authorized simulated phishing used to measure and improve user recognition and reporting behavior.

Answer C is incorrect because Situational awareness training would fit a different scenario. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.

 

Question 7

Which term describes education on organizational rules, responsibilities, and expected security behavior?

  1. Operational security awareness
  2. Removable-media training
  3. Policy and handbook training
  4. Unintentional behavior awareness

Correct Answer: C

 

Correct Answer

Answer C is correct because Policy and handbook training means education on organizational rules, responsibilities, and expected security behavior.

Incorrect Answers

Answer A is incorrect because Operational security awareness represents a different security function. Operational security awareness refers to training on avoiding unnecessary exposure of sensitive operational details.

Answer B is incorrect because Removable-media training would fit a different scenario. Removable-media training refers to guidance on safe handling of USB drives and other portable media.

Answer D is incorrect because Unintentional behavior awareness addresses a different requirement. Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents.

 

Question 8

To improve decisions when working in public, remote, or unusual environments, which security approach should be selected?

  1. Situational awareness training
  2. Social-engineering training
  3. Unintentional behavior awareness
  4. Password-management training

Correct Answer: A

 

Correct Answer

Answer A is correct because Situational awareness training means training that helps users recognize security context and adjust behavior to changing circumstances.

Incorrect Answers

Answer B is incorrect because Social-engineering training addresses a different requirement. Social-engineering training refers to education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure.

Answer C is incorrect because Unintentional behavior awareness would fit a different scenario. Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents.

Answer D is incorrect because Password-management training addresses a different security requirement. Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling.

 

Question 9

Which term describes education on indicators and reporting related to malicious or negligent trusted users?

  1. Insider-threat awareness
  2. Unintentional behavior awareness
  3. Social-engineering training
  4. Suspicious-message reporting

Correct Answer: A

 

Correct Answer

Answer A is correct because Insider-threat awareness means education on indicators and reporting related to malicious or negligent trusted users.

Incorrect Answers

Answer B is incorrect because Unintentional behavior awareness represents a different security function. Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents.

Answer C is incorrect because Social-engineering training would fit a different scenario. Social-engineering training refers to education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure.

Answer D is incorrect because Suspicious-message reporting addresses a different requirement. Suspicious-message reporting refers to a defined method for users to submit potentially malicious messages to security teams.

 

Question 10

To reduce compromise caused by weak, reused, or mishandled passwords, which security approach should be selected?

  1. Password-management training
  2. Remote-work security training
  3. Situational awareness training
  4. Removable-media training

Correct Answer: A

 

Correct Answer

Answer A is correct because Password-management training means guidance on unique credentials, password managers, MFA, and safe credential handling.

Incorrect Answers

Answer B is incorrect because Remote-work security training addresses a different requirement. Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices.

Answer C is incorrect because Situational awareness training addresses a different security requirement. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.

Answer D is incorrect because Removable-media training would fit a different scenario. Removable-media training refers to guidance on safe handling of USB drives and other portable media.

 

Question 11

Which term describes guidance on safe handling of USB drives and other portable media?

  1. Phishing recognition
  2. Removable-media training
  3. Unintentional behavior awareness
  4. Policy and handbook training

Correct Answer: B

 

Correct Answer

Answer B is correct because Removable-media training means guidance on safe handling of USB drives and other portable media.

Incorrect Answers

Answer A is incorrect because Phishing recognition would fit a different scenario. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.

Answer C is incorrect because Unintentional behavior awareness addresses a different requirement. Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents.

Answer D is incorrect because Policy and handbook training represents a different security function. Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior.

 

Question 12

To help users resist nontechnical attacks that target human trust, which security approach should be selected?

  1. Unexpected behavior recognition
  2. Situational awareness training
  3. Social-engineering training
  4. Removable-media training

Correct Answer: C

 

Correct Answer

Answer C is correct because Social-engineering training means education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure.

Incorrect Answers

Answer A is incorrect because Unexpected behavior recognition would fit a different scenario. Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue.

Answer B is incorrect because Situational awareness training addresses a different requirement. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.

Answer D is incorrect because Removable-media training addresses a different security requirement. Removable-media training refers to guidance on safe handling of USB drives and other portable media.

 

Question 13

Which term describes training on avoiding unnecessary exposure of sensitive operational details?

  1. Social-engineering training
  2. Situational awareness training
  3. Operational security awareness
  4. Policy and handbook training

Correct Answer: C

 

Correct Answer

Answer C is correct because Operational security awareness means training on avoiding unnecessary exposure of sensitive operational details.

Incorrect Answers

Answer A is incorrect because Social-engineering training would fit a different scenario. Social-engineering training refers to education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure.

Answer B is incorrect because Situational awareness training addresses a different requirement. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.

Answer D is incorrect because Policy and handbook training represents a different security function. Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior.

 

Question 14

To reduce security risk in home, travel, and hybrid work environments, which security approach should be selected?

  1. Password-management training
  2. Remote-work security training
  3. Phishing simulation campaign
  4. Situational awareness training

Correct Answer: B

 

Correct Answer

Answer B is correct because Remote-work security training means guidance on protecting devices, networks, conversations, and data outside controlled offices.

Incorrect Answers

Answer A is incorrect because Password-management training addresses a different requirement. Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling.

Answer C is incorrect because Phishing simulation campaign would fit a different scenario. Phishing simulation campaign refers to authorized simulated phishing used to measure and improve user recognition and reporting behavior.

Answer D is incorrect because Situational awareness training addresses a different security requirement. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.

 

Question 15

Which term describes security education repeated periodically and updated for changing threats and policies?

  1. Phishing recognition
  2. Operational security awareness
  3. Recurring awareness training
  4. Social-engineering training

Correct Answer: C

 

Correct Answer

Answer C is correct because Recurring awareness training means security education repeated periodically and updated for changing threats and policies.

Incorrect Answers

Answer A is incorrect because Phishing recognition would fit a different scenario. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.

Answer B is incorrect because Operational security awareness addresses a different requirement. Operational security awareness refers to training on avoiding unnecessary exposure of sensitive operational details.

Answer D is incorrect because Social-engineering training represents a different security function. Social-engineering training refers to education on manipulation techniques such as impersonation, pretexting, urgency, and authority pressure.

 

Question 16

To train users and generate measurable awareness data, which security approach should be selected?

  1. Password-management training
  2. Phishing simulation campaign
  3. Situational awareness training
  4. Remote-work security training

Correct Answer: B

 

Correct Answer

Answer B is correct because Phishing simulation campaign means authorized simulated phishing used to measure and improve user recognition and reporting behavior.

Incorrect Answers

Answer A is incorrect because Password-management training would fit a different scenario. Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling.

Answer C is incorrect because Situational awareness training addresses a different requirement. Situational awareness training refers to training that helps users recognize security context and adjust behavior to changing circumstances.

Answer D is incorrect because Remote-work security training represents a different security function. Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices.

 

Question 17

Which term describes ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies?

  1. Phishing recognition
  2. Recurring awareness training
  3. Unexpected behavior recognition
  4. Risky behavior recognition

Correct Answer: A

 

Correct Answer

Answer A is correct because Phishing recognition means ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.

Incorrect Answers

Answer B is incorrect because Recurring awareness training addresses a different security requirement. Recurring awareness training refers to security education repeated periodically and updated for changing threats and policies.

Answer C is incorrect because Unexpected behavior recognition addresses a different requirement. Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue.

Answer D is incorrect because Risky behavior recognition would fit a different scenario. Risky behavior recognition refers to awareness of actions that materially increase security exposure.

 

Question 18

To turn employees into an early detection source and support rapid analysis, which security approach should be selected?

  1. Unintentional behavior awareness
  2. Unexpected behavior recognition
  3. Suspicious-message reporting
  4. Removable-media training

Correct Answer: C

 

Correct Answer

Answer C is correct because Suspicious-message reporting means a defined method for users to submit potentially malicious messages to security teams.

Incorrect Answers

Answer A is incorrect because Unintentional behavior awareness addresses a different requirement. Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents.

Answer B is incorrect because Unexpected behavior recognition represents a different security function. Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue.

Answer D is incorrect because Removable-media training would fit a different scenario. Removable-media training refers to guidance on safe handling of USB drives and other portable media.

 

Question 19

Which term describes awareness of actions that materially increase security exposure?

  1. Removable-media training
  2. Recurring awareness training
  3. Remote-work security training
  4. Risky behavior recognition

Correct Answer: D

 

Correct Answer

Answer D is correct because Risky behavior recognition means awareness of actions that materially increase security exposure.

Incorrect Answers

Answer A is incorrect because Removable-media training would fit a different scenario. Removable-media training refers to guidance on safe handling of USB drives and other portable media.

Answer B is incorrect because Recurring awareness training addresses a different requirement. Recurring awareness training refers to security education repeated periodically and updated for changing threats and policies.

Answer C is incorrect because Remote-work security training addresses a different security requirement. Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices.

 

Question 20

To encourage early reporting of anomalies rather than ignoring them, which security approach should be selected?

  1. Unexpected behavior recognition
  2. Phishing recognition
  3. Remote-work security training
  4. Risky behavior recognition

Correct Answer: A

 

Correct Answer

Answer A is correct because Unexpected behavior recognition means awareness that unusual system, message, or identity behavior may indicate a security issue.

Incorrect Answers

Answer B is incorrect because Phishing recognition would fit a different scenario. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.

Answer C is incorrect because Remote-work security training represents a different security function. Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices.

Answer D is incorrect because Risky behavior recognition addresses a different requirement. Risky behavior recognition refers to awareness of actions that materially increase security exposure.

 

Question 21

Which term describes training that addresses mistakes and accidental actions that can create security incidents?

  1. Policy and handbook training
  2. Unintentional behavior awareness
  3. Phishing simulation campaign
  4. Phishing recognition

Correct Answer: B

 

Correct Answer

Answer B is correct because Unintentional behavior awareness means training that addresses mistakes and accidental actions that can create security incidents.

Incorrect Answers

Answer A is incorrect because Policy and handbook training addresses a different security requirement. Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior.

Answer C is incorrect because Phishing simulation campaign addresses a different requirement. Phishing simulation campaign refers to authorized simulated phishing used to measure and improve user recognition and reporting behavior.

Answer D is incorrect because Phishing recognition would fit a different scenario. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.

 

Question 22

To ensure users understand mandatory procedures and acceptable use, which security approach should be selected?

  1. Risky behavior recognition
  2. Phishing recognition
  3. Unexpected behavior recognition
  4. Policy and handbook training

Correct Answer: D

 

Correct Answer

Answer D is correct because Policy and handbook training means education on organizational rules, responsibilities, and expected security behavior.

Incorrect Answers

Answer A is incorrect because Risky behavior recognition represents a different security function. Risky behavior recognition refers to awareness of actions that materially increase security exposure.

Answer B is incorrect because Phishing recognition addresses a different requirement. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.

Answer C is incorrect because Unexpected behavior recognition would fit a different scenario. Unexpected behavior recognition refers to awareness that unusual system, message, or identity behavior may indicate a security issue.

 

Question 23

Which term describes training that helps users recognize security context and adjust behavior to changing circumstances?

  1. Policy and handbook training
  2. Remote-work security training
  3. Situational awareness training
  4. Phishing simulation campaign

Correct Answer: C

 

Correct Answer

Answer C is correct because Situational awareness training means training that helps users recognize security context and adjust behavior to changing circumstances.

Incorrect Answers

Answer A is incorrect because Policy and handbook training addresses a different security requirement. Policy and handbook training refers to education on organizational rules, responsibilities, and expected security behavior.

Answer B is incorrect because Remote-work security training addresses a different requirement. Remote-work security training refers to guidance on protecting devices, networks, conversations, and data outside controlled offices.

Answer D is incorrect because Phishing simulation campaign would fit a different scenario. Phishing simulation campaign refers to authorized simulated phishing used to measure and improve user recognition and reporting behavior.

 

Question 24

To help employees identify concerning behavior without encouraging unsupported accusations, which security approach should be selected?

  1. Unintentional behavior awareness
  2. Risky behavior recognition
  3. Password-management training
  4. Insider-threat awareness

Correct Answer: D

 

Correct Answer

Answer D is correct because Insider-threat awareness means education on indicators and reporting related to malicious or negligent trusted users.

Incorrect Answers

Answer A is incorrect because Unintentional behavior awareness represents a different security function. Unintentional behavior awareness refers to training that addresses mistakes and accidental actions that can create security incidents.

Answer B is incorrect because Risky behavior recognition would fit a different scenario. Risky behavior recognition refers to awareness of actions that materially increase security exposure.

Answer C is incorrect because Password-management training addresses a different requirement. Password-management training refers to guidance on unique credentials, password managers, MFA, and safe credential handling.

 

Question 25

Which term describes guidance on unique credentials, password managers, MFA, and safe credential handling?

  1. Recurring awareness training
  2. Removable-media training
  3. Phishing recognition
  4. Password-management training

Correct Answer: D

 

Correct Answer

Answer D is correct because Password-management training means guidance on unique credentials, password managers, MFA, and safe credential handling.

Incorrect Answers

Answer A is incorrect because Recurring awareness training addresses a different requirement. Recurring awareness training refers to security education repeated periodically and updated for changing threats and policies.

Answer B is incorrect because Removable-media training addresses a different security requirement. Removable-media training refers to guidance on safe handling of USB drives and other portable media.

Answer C is incorrect because Phishing recognition would fit a different scenario. Phishing recognition refers to ability to identify suspicious senders, links, attachments, urgency, requests, or inconsistencies.

img