🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 8 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An organization migrating its customer data to AWS has suffered several recent spear-phishing attempts aimed at its finance employees. As the security administrator, you have been asked to roll out an awareness communication that is both cost-effective and tailored to this risk. Which action best aligns with SSCP best practices for matching security awareness content to specific organizational threats?

  • Schedule mandatory, in-person annual security classes for all staff that cover every known social-engineering technique, regardless of job function.

  • Create short, role-based email micro-trainings for the finance staff that explain how to recognize payment-fraud phishing, and reinforce them with periodic simulated phishing messages that record user clicks to measure improvement.

  • Block all external email to the finance department until a comprehensive corporate training program can be developed and deployed.

  • Distribute the full NIST phishing guidance document to every employee company-wide and require a signed acknowledgment within 24 hours.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot