5.6 Given a scenario, implement security awareness practices
Objective 5.6 sits in Security Program Management and Oversight, which carries 20% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.
Objective title verbatim from the official objectives. CompTIA exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
During a phishing simulation, a user clicks a link and lands on a page styled like the company intranet, which asks for a username and password. Which social engineering technique is being simulated?
The concept
Attack simulation training models specific social engineering techniques that mirror real phishing tactics.
Why this answer
Credential Harvest simulates an attacker directing a user to a themed fake login page that requests a username and password, matching the scenario described.
- ADrive-by-url runs background code without ever prompting for a password, not matching this scenario.
- BLink to Malware points to a file on a sharing site that triggers code execution, not a login prompt.
- Correct. A themed sign-in page that captures what is typed.
- DOAuth Consent Grant asks the user to approve application access rather than enter a password.
Now you: objective 5.6 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An organization keeps a secret value in a hardware security module and combines it with every stored password hash, so a database-only breach cannot be used to crack passwords. What is this secret value called?
Sample question 2 of 3
A simulated phishing message links to a well-known website. After the user clicks, code runs quietly in the background gathering device information, and no password prompt ever appears. Which technique is this?
Sample question 3 of 3
A simulated message contains a link. After clicking, the user is asked to approve a third-party application's request for mailbox access, rather than being asked for a password. Which technique is this?
That’s 3 of the full Security+ bank.
Keep going free: 10 questions per certification in bank practice, with no account.
Continue practicingRead the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Security Program Management and Oversight
- 5.1 5.1 Summarize elements of effective security governance
- 5.2 5.2 Explain elements of the risk management process
- 5.3 5.3 Explain the processes associated with third-party risk assessment and management
- 5.4 5.4 Summarize elements of effective security compliance
- 5.5 5.5 Explain types and purposes of audits and assessments