What is included in a security awareness program's communication element?
Which of the following is the most likely to be included as an element of communication in a security awareness program?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your ability to distinguish communication elements (reporting) from technical controls (detection, verification) and offensive testing (social engineering penetration tests).
A security awareness program's communication element focuses on enabling employees to report suspicious activities such as phishing attempts. Community consensus confirms that reporting mechanisms are the core communication component designed for the average employee.
Candidates may choose C (verifying wire transfer data) because it involves communication, but it is a procedural control for finance staff rather than a company-wide awareness communication element.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A directly addresses the communication element of a security awareness program by establishing a clear channel for employees to report phishing and suspicious activity. Security awareness programs are designed for the entire workforce, and reporting mechanisms are the primary way employees communicate security concerns to the security team. Community comment [2] rightly highlights that "reporting" is the only option that embodies two-way communication between employees and the security team.Why the Other Options Are Wrong
Option B describes a technical detection capability (UEBA/anomalous behavior recognition) implemented by security tools, not a communication element for employees. Option C is a business process control specific to finance or accounting personnel handling wire transfers, not a general awareness communication element. Option D describes an offensive security activity (penetration testing via social engineering) performed by third-party testers, which is not a communication element of an awareness program aimed at employees.Community Comment Notes
Comment [1] (13 likes) provides the clearest reasoning: the awareness program targets the average employee with limited technical skills, making B, C, and D irrelevant because they are tasks for the cybersecurity or finance teams. Comment [2] reinforces that the keyword "communication" maps directly to reporting. The community unanimously supports A with 100% of votes.Official Reference
Exam Strategy
When a question asks about security awareness program elements, focus on the target audience—average employees. Eliminate options that describe technical controls, specialized procedures, or offensive testing, as awareness programs emphasize simple, actionable communication like reporting.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →