How to reduce employees visiting deceptive credential-harvesting sites?

A security report shows that during a two-week test period, 80% of employees unwittingly disclosed their SSO credentials when accessing an external website. The organization purposely created the website to simulate a cost-free password complexity test. Which of the following would best help reduce the number of visits to similar websites in the future?

  1. Block all outbound traffic from the intranet.
  2. Introduce a campaign to recognize phishing attempts. Source Reference Answer
  3. Restrict internet access for the employees who disclosed credentials.
  4. Implement a deny list of websites.

Community Votes

B
67%
D
33%

67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

CompTIA tests whether candidates recognize that social engineering and deceptive-site attacks are best mitigated through user awareness training, not just technical controls like deny lists.

This question tests the best control to reduce visits to deceptive credential-harvesting sites after a simulated password-complexity test revealed 80% of employees disclosed SSO credentials. Community consensus favors security awareness training (phishing recognition) over technical blocks because user behavior is the root cause.

Many choose D (deny list of websites) because it seems to directly block 'similar websites,' but deny lists are easily bypassed and do not address the human factor that caused the disclosures.

Community Discussion (3 comments)

Konversation 👍 1 Selected: B
CompTIA expects for similar questions, that a "user training" is the best solution against phishing or similar activities. That's why I tend slightly to B over D.
itsgonnabemay 👍 1 Selected: D
The question says that the employees disclosed credentials when visiting an external website, not necessarily thorugh email (phishing). To prevent employees from visiting similar websites, it'd be best to implement a deny list of similar websites.
9149f41 👍 1 Selected: B
company delivered a fake Honeypot internal website to catch the staff who disbursed the SSO. So the activities relevant to phishing.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B, introducing a campaign to recognize phishing attempts, directly addresses the root cause: employees failed to recognize a deceptive site mimicking a legitimate password-complexity test. CompTIA consistently favors administrative controls like security awareness training for social-engineering scenarios because they change user behavior. Training equips employees to spot deceptive URLs, suspicious contexts, and credential-harvesting tactics in the future.

Why the Other Options Are Wrong

Option A (block all outbound traffic) is impractical and would break business operations; it is a disproportionate response. Option C (restrict internet for offenders) is punitive, does not scale, and fails to educate the rest of the workforce. Option D (deny list) is a weak technical control—attackers register new domains constantly, so a deny list is always one step behind and does not teach users to think critically.

Community Comment Notes

Commenters are split, with 67 votes for B and 33 for D. Comment [2] argues the site was not a phishing email, so a deny list is better; however, the scenario is still a social-engineering/deceptive-site attack, which CompTIA classifies under the phishing umbrella. Comments [1] and [3] correctly note that CompTIA expects 'user training' as the primary defense against phishing-like activities, reinforcing why B is the exam-correct answer.

Official Reference

Exam Strategy

When a question describes employees falling for a deceptive site or social-engineering test, default to security awareness training as the best long-term control. Technical blocks like deny lists are tempting but are reactive, easily bypassed, and rarely the CompTIA-preferred answer for human-factor problems.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide