Phishing simulation exercises are designed to educate users and reduce the likelihood of them falling for real phishing attacks. This is considered apreventive control, as it aims to stop incidents before they occur by changing behavior. Reference:CRISC Manual - Domain 3, Slide 275-276