What is the First Step to Increase Security Awareness After Account Compromises?

After a series of account compromises and credential misuse, a company hires a security manager to develop a security program. Which of the following steps should the security manager take first to increase security awareness?

  1. Evaluate tools that identify risky behavior and distribute reports on the findings. Source Reference Answer
  2. Send quarterly newsletters that explain the importance of password management.
  3. Develop phishing campaigns and notify the management team of any successes.
  4. Update policies and handbooks to ensure all employees are informed of the new procedures.

Community Votes

A
57%
D
43%

57% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the 'assess before act' principle in human risk management; the trap is choosing policy updates (D) when CompTIA expects you to gather baseline data on risky behaviors to make awareness training actionable.

This question examines the foundational step in launching a security awareness initiative following credential misuse, highlighting the need for behavioral assessment before training deployment. Community consensus leans toward evaluating risky behaviors first to tailor awareness efforts effectively.

Option D is frequently chosen because candidates assume formalizing policies must precede operational changes. However, updating handbooks without first identifying the specific risky behaviors causing the breaches results in generic, ineffective awareness campaigns.

Community Discussion (5 comments)

Konversation 👍 1 Selected: D
Answer D. Sec+ Student Guide: Chapter "Cybersecurity Framework" in accordance with NIST Cyber Framework: The first step is "Identify—develop security policies and capabilities. Evaluate risks, threats, and vulnerabilities and recommend security controls to mitigate them." Detection (A) is the third step. That's also what happens in real life. When you start as a manager or as an auditor, you not start directly with implementing tools. You first read and adjust the existing policies and guidelines. Good luck on the exam!
prabh1251 👍 1 Selected: C
Start with C, Then Move to D. 1️⃣ First: Phishing simulations & hands-on training → Immediate impact & awareness. 2️⃣ Then: Update policies & handbooks → Reinforce expectations based on real observations
Turrtle 👍 2 Selected: D
Wont A be focusing more on monitoring behavior, not raising awareness. Employees must first understand security best practices before assessing their behavior so D makes sense so that employees understand expectations, best practices, and consequences for security violations. security awareness
test_arrow 👍 2 Selected: A
I would say A here The first step in increasing security awareness is to identify the root causes of security issues, such as poor password hygiene, phishing susceptibility, or risky user behavior. Evaluating tools that monitor user behavior (e.g., login anomalies, credential reuse, and failed authentication attempts) helps the security manager understand where the biggest risks exist. Distributing reports on these findings provides data-driven insights to employees and management, making security awareness efforts more impactful. Why Not the Other Options? B - Newsletters provide passive awareness, but they do not actively identify or address specific risky behaviors. C - Phishing simulations are useful but focus only on phishing risks. A broader risk assessment is needed first. D - Policies are necessary, but updating documents alone does not actively increase awareness or change behavior.
PjoterK 👍 2 Selected: A
Correct Answer: A. Evaluate tools that identify risky behavior and distribute reports on the findings.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Assessing Human Risk Before Training

In CompTIA Security+, developing a security awareness program follows a structured, risk-based lifecycle. The scenario describes recent account compromises and credential misuse, indicating a clear human factor vulnerability. To effectively increase security awareness, the security manager must first understand what specific behaviors are failing.

Why A is Correct: Evaluating tools that identify risky behavior (such as failed logins, credential reuse, or anomalous access patterns) provides the baseline data necessary to design targeted awareness initiatives. As noted by community experts, distributing reports on these findings allows the organization to pinpoint exactly where employees are struggling, ensuring that subsequent training addresses real-world threats rather than hypothetical ones. This aligns with SY0-701 Objective 1.3, which emphasizes tailoring human risk management strategies based on continuous assessment.

Why Other Options Are Incorrect:

  • Option B relies on passive, generalized communication (quarterly newsletters) that rarely drives meaningful behavioral change or addresses the specific compromises mentioned.
  • Option C focuses on phishing simulations but incorrectly targets notifying management of successes rather than using the results to train employees. Simulations are a validation tool, not a primary awareness-building step.
  • Option D is the most common distractor. While updating policies is essential, CompTIA prioritizes assessment and risk identification before procedural enforcement. Without data from Option A, policy updates remain untargeted and fail to address the actual root causes of the credential misuse.

Official Reference

Exam Strategy

When a question asks for the "first step" in implementing a security control or program, always prioritize options involving assessment, discovery, or risk identification over implementation or policy creation. CompTIA consistently rewards the data-driven approach: measure the problem, then design the solution.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide