exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 583 discussion

Actual exam question from CompTIA's SY0-701
Question #: 554
Topic #: 1
[All SY0-701 Questions]

After a series of account compromises and credential misuse, a company hires a security manager to develop a security program. Which of the following steps should the security manager take first to increase security awareness?

  • A. Evaluate tools that identify risky behavior and distribute reports on the findings.
  • B. Send quarterly newsletters that explain the importance of password management.
  • C. Develop phishing campaigns and notify the management team of any successes.
  • D. Update policies and handbooks to ensure all employees are informed of the new procedures.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Zeez3377
3 weeks, 1 day ago
Selected Answer: D
I feel like this is might be a wording one. Why would you be evaluating the tools and not evaluate using the tools? "A. Evaluate tools that identify risky behavior and distribute reports on the findings." Also on one of CompTIAs articles in the protips section of phising, it says to use policies to inform users about policies and procedures, then states testing your users https://www.comptia.org/content/articles/cybersecurity-awareness-training#:~:text=Proactive%20security%20awareness%20involves%20checking,the%20email%20for%20anything%20suspicious.
upvoted 1 times
...
Konversation
1 month, 1 week ago
Selected Answer: D
Answer D. Sec+ Student Guide: Chapter "Cybersecurity Framework" in accordance with NIST Cyber Framework: The first step is "Identify—develop security policies and capabilities. Evaluate risks, threats, and vulnerabilities and recommend security controls to mitigate them." Detection (A) is the third step. That's also what happens in real life. When you start as a manager or as an auditor, you not start directly with implementing tools. You first read and adjust the existing policies and guidelines. Good luck on the exam!
upvoted 3 times
...
prabh1251
1 month, 3 weeks ago
Selected Answer: C
Start with C, Then Move to D. 1️⃣ First: Phishing simulations & hands-on training → Immediate impact & awareness. 2️⃣ Then: Update policies & handbooks → Reinforce expectations based on real observations
upvoted 1 times
...
Turrtle
2 months, 2 weeks ago
Selected Answer: D
Wont A be focusing more on monitoring behavior, not raising awareness. Employees must first understand security best practices before assessing their behavior so D makes sense so that employees understand expectations, best practices, and consequences for security violations. security awareness
upvoted 2 times
jaylom
1 month, 2 weeks ago
I think the keyword here is "step to take first", and following the nature of gathering information is always the first step, I believe that it is better to gather findings of risky behavior first, and then establish/update policies based on these findings.
upvoted 1 times
...
...
test_arrow
2 months, 3 weeks ago
Selected Answer: A
I would say A here The first step in increasing security awareness is to identify the root causes of security issues, such as poor password hygiene, phishing susceptibility, or risky user behavior. Evaluating tools that monitor user behavior (e.g., login anomalies, credential reuse, and failed authentication attempts) helps the security manager understand where the biggest risks exist. Distributing reports on these findings provides data-driven insights to employees and management, making security awareness efforts more impactful. Why Not the Other Options? B - Newsletters provide passive awareness, but they do not actively identify or address specific risky behaviors. C - Phishing simulations are useful but focus only on phishing risks. A broader risk assessment is needed first. D - Policies are necessary, but updating documents alone does not actively increase awareness or change behavior.
upvoted 2 times
...
PjoterK
2 months, 3 weeks ago
Selected Answer: A
Correct Answer: A. Evaluate tools that identify risky behavior and distribute reports on the findings.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago