After a series of account compromises and credential misuse, a company hires a security manager to develop a security program. Which of the following steps should the security manager take first to increase security awareness?
Choose an answer
Tap an option to check your answer.
Correct answer: Update policies and handbooks to ensure all employees are informed of the new procedures..
Why this is the answer
The correct answer is to update policies and handbooks because establishing clear, documented guidelines is the foundational step for any security program, especially after a series of compromises. Policies define expectations and procedures, providing a framework for all subsequent security awareness efforts. Without updated policies, other initiatives lack official backing and consistent direction. Evaluating tools for risky behavior is premature without established policies to define what constitutes risky behavior. Sending quarterly newsletters is a good awareness tactic but is less effective without foundational policies. Developing phishing campaigns is a valuable training and testing method, but it should follow the establishment of clear policies and initial awareness training, not precede it as the first step.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed