After a phishing campaign, your SOC receives several early user reports, and one user clicked a link before containment. You must send a follow-up communication that improves future reporting behavior without blaming individuals. Which communication approach is most appropriate?
Select an answer to reveal the explanation.
Short Explanation
Think of phishing follow-up like a fire drill: you want people to shout 'fire' faster, not hide because they're scared. A blameless, anonymous thank-you and lesson learned tells users reporting is safe and useful. Blame just trains them to stay quiet next time.
Full Explanation
After a phishing incident, follow-up communication should be treated as a behavioral control, not a disciplinary artifact. The mechanism is simple: users report more often when they perceive reporting as low-risk, useful, and appreciated. An anonymous lessons-learned message that thanks early reporters and explains what indicators were seen reinforces the desired behavior across the whole population while preserving privacy and avoiding a culture of concealment.
A named report identifying who clicked is wrong because it turns incident response into public shaming, which discourages voluntary reporting and may create privacy and HR issues. A mandatory training notice sent only to users who clicked is wrong because remediation should be risk-based and proportionate, and selective punishment narrows awareness instead of improving organization-wide reporting. A management summary requesting formal disciplinary action is wrong unless a policy violation is confirmed and the process requires it; in a learning-focused phishing response, the primary goal is to strengthen detection and reporting, not to assign personal fault.
Exam caveat: CompTIA expects analysts to choose communication that supports trust and future reporting, not punitive exposure. Operational check: Send a brief, anonymized summary that thanks reporters, lists the phishing indicators, and states how to report suspicious messages again.