An organization recently launched simulated phishing exercises to evaluate its human risk management program. Rather than relying solely on training completion rates, the security team wants to assess active employee engagement during a simulated attack. Which of the following metrics best indicates a positive security awareness outcome?
- An increase in the percentage of employees who report simulated phishing emails using the reporting toolAnswer
- BAn increase in the number of automated network firewall rules deployed to block external IP addresses
- CAn increase in employee ability to distinguish technical differences between vishing and smishing attack vectors
- DAn increase in the installation rate of endpoint antimalware agents across corporate desktop systems
Answer
An increase in the percentage of employees who report simulated phishing emails using the reporting tool
High reporting rates of simulated phishing emails indicate that users recognize social engineering indicators and know how to report suspicious activity promptly, directly mitigating human risk.
Step-by-Step Solution
Key Concept
Security Awareness Program Metrics and Phishing Reporting
Estimated Time:1m 0s