Given a scenario, implement security awareness practices
Phishing recognition and reporting, anomalous behaviour, user guidance, and measuring whether training worked.
- Reading time
- 16 min read
- Flashcards
- 14 cards
- Practice questions
- 8 questions · 2 PBQs
The final objective, and the one that closes a loop: 2.2 established that human vectors have no technical fix. This is the fix.
Why it matters
Every other control in the exam can be bought and configured. Security awareness is the only mitigation for phishing, pretexting and the rest of the social engineering set — and phishing remains the most common route into an organisation.
Phishing programmes
Three parts:
Campaigns — simulated phishing sent to staff to measure susceptibility and provide practice in a safe setting. Recognising — teaching the indicators: urgency, authority, mismatched sender, unexpected attachment, links that do not match their text. Responding — teaching what to do, which is report it.
Check yourself
A simulated phishing programme punishes anyone who clicks. Reporting of real phishing subsequently falls. What went wrong?
Anomalous behaviour recognition
Training staff to notice and report three categories:
- Risky behaviour — knowingly cutting corners, sharing credentials, disabling controls
- Unexpected behaviour — a colleague acting out of character, or a system behaving oddly
- Unintentional behaviour — honest mistakes, such as sending data to the wrong recipient
The purpose is turning the workforce into sensors. Staff notice things monitoring cannot: a colleague's changed circumstances, someone in the building who does not belong.
User guidance topics
CompTIA lists these specifically:
- Policy and handbooks — the AUP from 5.1, and what it requires in practice
- Situational awareness — noticing what is happening around you
- Insider threat — recognising and reporting the indicators from 2.1
- Password management — length over complexity, uniqueness, password managers (4.6)
- Removable media and cables — the dropped USB from 2.2, plus malicious charging cables
- Social engineering — the techniques and principles from 2.2
- Operational security (OPSEC) — not disclosing information that helps an attacker, including on social media
- Hybrid and remote work — home network security, shoulder surfing in public, device handling
Check yourself
An employee posts a photo of their new work laptop showing their screen with an internal system visible. Which training topic addresses this?
Reporting and monitoring
Initial — baseline training, typically at onboarding. Recurring — ongoing training, because threats change and knowledge decays.
Monitoring measures whether the programme works: click rates, reporting rates, and how quickly reports arrive. Metrics turn awareness from an activity into a control you can evaluate.
Development and execution
Development — building the programme: identifying what staff need, choosing content, setting a schedule. Execution — delivering it, and tracking completion.
The recurring exam theme is that awareness is a programme, not an event. Annual click-through training that nobody remembers satisfies a checkbox and changes no behaviour.
Where this connects
- 2.1 — insider threat indicators staff should recognise
- 2.2 — the social engineering techniques being defended against
- 4.6 — password management guidance
- 5.1 — the acceptable use policy staff are trained on
That spread is why this objective is worth more marks than its length suggests. It is the human-facing half of most of the exam.