Security+
5.6Security Program Management and Oversight · 20% of exam

Given a scenario, implement security awareness practices

Phishing recognition and reporting, anomalous behaviour, user guidance, and measuring whether training worked.

Reading time
16 min read
Flashcards
14 cards
Practice questions
8 questions · 2 PBQs

The final objective, and the one that closes a loop: 2.2 established that human vectors have no technical fix. This is the fix.

Why it matters

Every other control in the exam can be bought and configured. Security awareness is the only mitigation for phishing, pretexting and the rest of the social engineering set — and phishing remains the most common route into an organisation.

Phishing programmes

Three parts:

Campaigns — simulated phishing sent to staff to measure susceptibility and provide practice in a safe setting. Recognising — teaching the indicators: urgency, authority, mismatched sender, unexpected attachment, links that do not match their text. Responding — teaching what to do, which is report it.

Check yourself

A simulated phishing programme punishes anyone who clicks. Reporting of real phishing subsequently falls. What went wrong?

Anomalous behaviour recognition

Training staff to notice and report three categories:

  • Risky behaviour — knowingly cutting corners, sharing credentials, disabling controls
  • Unexpected behaviour — a colleague acting out of character, or a system behaving oddly
  • Unintentional behaviour — honest mistakes, such as sending data to the wrong recipient

The purpose is turning the workforce into sensors. Staff notice things monitoring cannot: a colleague's changed circumstances, someone in the building who does not belong.

User guidance topics

CompTIA lists these specifically:

  • Policy and handbooks — the AUP from 5.1, and what it requires in practice
  • Situational awareness — noticing what is happening around you
  • Insider threat — recognising and reporting the indicators from 2.1
  • Password management — length over complexity, uniqueness, password managers (4.6)
  • Removable media and cables — the dropped USB from 2.2, plus malicious charging cables
  • Social engineering — the techniques and principles from 2.2
  • Operational security (OPSEC) — not disclosing information that helps an attacker, including on social media
  • Hybrid and remote work — home network security, shoulder surfing in public, device handling

Check yourself

An employee posts a photo of their new work laptop showing their screen with an internal system visible. Which training topic addresses this?

Reporting and monitoring

Initial — baseline training, typically at onboarding. Recurring — ongoing training, because threats change and knowledge decays.

Monitoring measures whether the programme works: click rates, reporting rates, and how quickly reports arrive. Metrics turn awareness from an activity into a control you can evaluate.

Development and execution

Development — building the programme: identifying what staff need, choosing content, setting a schedule. Execution — delivering it, and tracking completion.

The recurring exam theme is that awareness is a programme, not an event. Annual click-through training that nobody remembers satisfies a checkbox and changes no behaviour.

Where this connects

  • 2.1 — insider threat indicators staff should recognise
  • 2.2 — the social engineering techniques being defended against
  • 4.6 — password management guidance
  • 5.1 — the acceptable use policy staff are trained on

That spread is why this objective is worth more marks than its length suggests. It is the human-facing half of most of the exam.