How to reduce employees visiting deceptive credential-harvesting sites?
A security report shows that during a two-week test period, 80% of employees unwittingly disclosed their SSO credentials when accessing an external website. The organization purposely created the website to simulate a cost-free password complexity test. Which of the following would best help reduce the number of visits to similar websites in the future?
Community Votes
67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
CompTIA tests whether candidates recognize that social engineering and deceptive-site attacks are best mitigated through user awareness training, not just technical controls like deny lists.
This question tests the best control to reduce visits to deceptive credential-harvesting sites after a simulated password-complexity test revealed 80% of employees disclosed SSO credentials. Community consensus favors security awareness training (phishing recognition) over technical blocks because user behavior is the root cause.
Many choose D (deny list of websites) because it seems to directly block 'similar websites,' but deny lists are easily bypassed and do not address the human factor that caused the disclosures.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option B, introducing a campaign to recognize phishing attempts, directly addresses the root cause: employees failed to recognize a deceptive site mimicking a legitimate password-complexity test. CompTIA consistently favors administrative controls like security awareness training for social-engineering scenarios because they change user behavior. Training equips employees to spot deceptive URLs, suspicious contexts, and credential-harvesting tactics in the future.Why the Other Options Are Wrong
Option A (block all outbound traffic) is impractical and would break business operations; it is a disproportionate response. Option C (restrict internet for offenders) is punitive, does not scale, and fails to educate the rest of the workforce. Option D (deny list) is a weak technical control—attackers register new domains constantly, so a deny list is always one step behind and does not teach users to think critically.Community Comment Notes
Commenters are split, with 67 votes for B and 33 for D. Comment [2] argues the site was not a phishing email, so a deny list is better; however, the scenario is still a social-engineering/deceptive-site attack, which CompTIA classifies under the phishing umbrella. Comments [1] and [3] correctly note that CompTIA expects 'user training' as the primary defense against phishing-like activities, reinforcing why B is the exam-correct answer.Official Reference
Exam Strategy
When a question describes employees falling for a deceptive site or social-engineering test, default to security awareness training as the best long-term control. Technical blocks like deny lists are tempting but are reactive, easily bypassed, and rarely the CompTIA-preferred answer for human-factor problems.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →