How to Improve Security Posture After Employees Click Phishing Links?
A company is concerned about employees unintentionally introducing malware into the network. The company identified fifty employees who clicked on a link embedded in an email sent by the internal IT department. Which of the following should the company implement to best improve its security posture?
Community Votes
80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether candidates recognize that post-failure remediation requires proactive user education rather than repeating simulations or deploying unrelated infrastructure controls.
This question evaluates the appropriate organizational response when employees fail a phishing exercise, highlighting that targeted user education is superior to redundant testing or misaligned technical controls. Community consensus strongly supports social engineering training as the most effective next step.
Candidates frequently select simulated phishing campaigns (Option C), mistakenly believing that repeated testing will immediately correct behavior, while overlooking the explicit statement that a simulation was already conducted and failing to address the underlying knowledge gap.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Correct Answer: Social Engineering Training
The scenario explicitly states that the internal IT department already sent an email containing a clickable link to test employee vigilance. This is a classic simulated phishing campaign. Since fifty employees already fell for it, conducting another simulation (Option C) would be redundant and inefficient. CompTIA Security+ consistently emphasizes a progressive security awareness lifecycle: identify vulnerabilities through testing, then address them with targeted training, and finally re-evaluate. Social engineering training directly educates staff on recognizing manipulation tactics, suspicious links, and safe browsing practices, making it the most logical and impactful next step to improve the organization's overall security posture.
Why Other Options Are Incorrect
SPF Configuration (Option B) is a DNS-based email authentication protocol designed to prevent domain spoofing and unauthorized senders. While valuable for email security hygiene, SPF operates at the mail server level and does not protect users from clicking malicious links sent by authenticated or seemingly legitimate internal addresses. It also fails to address the core issue of unintentional malware introduction caused by human error.
Simulated Phishing Campaign (Option C) is tempting because it directly targets phishing behavior, but the prompt confirms this activity has already occurred. Running additional simulations without first providing education violates best practices for security awareness programs and can lead to alert fatigue or frustration among staff. Testing without training yields diminishing returns.
Insider Threat Awareness (Option D) focuses on identifying and mitigating intentional malicious activities by employees, contractors, or partners, such as data exfiltration or sabotage. The scenario describes unintentional malware introduction due to lack of awareness, which falls squarely under social engineering and general security awareness, not insider threat management.
As noted by the community, several candidates initially gravitated toward SPF or repeated simulations, but the consensus correctly identifies that behavioral correction through structured training is the definitive CompTIA-preferred solution for addressing human-risk vulnerabilities.
Official Reference
- https://www.comptia.org/certifications/security-plus
- https://csrc.nist.gov/publications/detail/sp/800-50/final
- RFC 7208 - Sender Policy Framework (SPF)
- CompTIA Security+ SY0-701 Objectives: Domain 1.0 - General Security Principles, specifically Security Awareness and Training
Exam Strategy
Always scan the scenario for temporal or procedural keywords like 'already conducted,' 'recently tested,' or 'unintentional.' When a control has clearly been deployed, the exam expects you to select the complementary or remedial action (such as training or policy updates) rather than repeating the same measure. Match the solution type to the root cause: human error requires education, while infrastructure gaps require technical controls.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →