What is the First Step to Increase Security Awareness After Account Compromises?
After a series of account compromises and credential misuse, a company hires a security manager to develop a security program. Which of the following steps should the security manager take first to increase security awareness?
Community Votes
57% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the 'assess before act' principle in human risk management; the trap is choosing policy updates (D) when CompTIA expects you to gather baseline data on risky behaviors to make awareness training actionable.
This question examines the foundational step in launching a security awareness initiative following credential misuse, highlighting the need for behavioral assessment before training deployment. Community consensus leans toward evaluating risky behaviors first to tailor awareness efforts effectively.
Option D is frequently chosen because candidates assume formalizing policies must precede operational changes. However, updating handbooks without first identifying the specific risky behaviors causing the breaches results in generic, ineffective awareness campaigns.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Assessing Human Risk Before Training
In CompTIA Security+, developing a security awareness program follows a structured, risk-based lifecycle. The scenario describes recent account compromises and credential misuse, indicating a clear human factor vulnerability. To effectively increase security awareness, the security manager must first understand what specific behaviors are failing.Why A is Correct: Evaluating tools that identify risky behavior (such as failed logins, credential reuse, or anomalous access patterns) provides the baseline data necessary to design targeted awareness initiatives. As noted by community experts, distributing reports on these findings allows the organization to pinpoint exactly where employees are struggling, ensuring that subsequent training addresses real-world threats rather than hypothetical ones. This aligns with SY0-701 Objective 1.3, which emphasizes tailoring human risk management strategies based on continuous assessment.
Why Other Options Are Incorrect:
- Option B relies on passive, generalized communication (quarterly newsletters) that rarely drives meaningful behavioral change or addresses the specific compromises mentioned.
- Option C focuses on phishing simulations but incorrectly targets notifying management of successes rather than using the results to train employees. Simulations are a validation tool, not a primary awareness-building step.
- Option D is the most common distractor. While updating policies is essential, CompTIA prioritizes assessment and risk identification before procedural enforcement. Without data from Option A, policy updates remain untargeted and fail to address the actual root causes of the credential misuse.
Official Reference
Exam Strategy
When a question asks for the "first step" in implementing a security control or program, always prioritize options involving assessment, discovery, or risk identification over implementation or policy creation. CompTIA consistently rewards the data-driven approach: measure the problem, then design the solution.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →