Objective 5.6SY0-701

5.6 Given a scenario, implement security awareness practices

Objective 5.6 sits in Security Program Management and Oversight, which carries 20% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Security Program Management and OversightModerate

During a phishing simulation, a user clicks a link and lands on a page styled like the company intranet, which asks for a username and password. Which social engineering technique is being simulated?

Correct.

The concept

Attack simulation training models specific social engineering techniques that mirror real phishing tactics.

Why this answer

Credential Harvest simulates an attacker directing a user to a themed fake login page that requests a username and password, matching the scenario described.

  • ADrive-by-url runs background code without ever prompting for a password, not matching this scenario.
  • BLink to Malware points to a file on a sharing site that triggers code execution, not a login prompt.
  • Correct. A themed sign-in page that captures what is typed.
  • DOAuth Consent Grant asks the user to approve application access rather than enter a password.
Read the sourceMicrosoft Learn: Attack simulation training
Verified against learn.microsoft.com · 2026-07-27
phishing-trainingsocial-engineeringattack-simulation

Now you: objective 5.6 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Security Program Management and OversightModerate

An organization keeps a secret value in a hardware security module and combines it with every stored password hash, so a database-only breach cannot be used to crack passwords. What is this secret value called?

Sample question 2 of 3

Security Program Management and OversightModerate

A simulated phishing message links to a well-known website. After the user clicks, code runs quietly in the background gathering device information, and no password prompt ever appears. Which technique is this?

Sample question 3 of 3

Security Program Management and OversightHard

A simulated message contains a link. After clicking, the user is asked to approve a third-party application's request for mailbox access, rather than being asked for a password. Which technique is this?

That’s 3 of the full Security+ bank.

Keep going free: 10 questions per certification in bank practice, with no account.

Continue practicing

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Program Management and Oversight