Courseiva

GSEC Security Frameworks and CIS Controls Practice Question

A healthcare organization is implementing CIS Control 14: Security Awareness and Skills Training. The security manager needs to ensure that the training program effectively reduces phishing susceptibility among employees. Which of the following approaches best aligns with the control's requirements?

⚠ Common exam trap

The trap here is equating security awareness with periodic training or communications, when CIS Control 14 specifically calls for simulated phishing and continuous reinforcement to effectively change behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a phishing simulation program with regular campaigns, provide immediate feedback to users who click, and track improvement over time.

CIS Control 14 emphasizes continuous security awareness training that includes simulated phishing exercises to test and reinforce employee skills. A program with regular phishing simulations, immediate feedback, and tracking of improvement directly measures and reduces susceptibility. Other options are either too infrequent or passive, failing to provide the practical, ongoing reinforcement that the control requires.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a phishing simulation program with regular campaigns, provide immediate feedback to users who click, and track improvement over time.

    Why this is correct

    This approach aligns with CIS Control 14 by providing continuous, practical training through simulated phishing attacks. Immediate feedback educates users in the moment, and tracking improvement measures the program's effectiveness. It goes beyond mere completion tracking to actively reduce susceptibility by reinforcing secure behavior and adapting training based on results.

  • ✗

    Require employees to complete a computer-based training module on phishing once per quarter and pass a quiz.

    Why it's wrong here

    Quarterly training with a quiz is more frequent than annual but still lacks the continuous reinforcement and real-world simulation that CIS Control 14 advocates. Quizzes may test knowledge but not behavior. The control requires simulated phishing to practice recognition and reporting, which this option does not include, making it less effective at reducing actual susceptibility.

  • ✗

    Send monthly security newsletters to all staff highlighting recent phishing trends and best practices.

    Why it's wrong here

    Newsletters can raise awareness but are passive and do not provide the interactive, hands-on practice required to reduce phishing susceptibility. CIS Control 14 emphasizes simulated phishing and role-based training, not just informational communications. Without active testing and feedback, the organization cannot measure or improve employee resilience to phishing.

  • ✗

    Conduct annual security awareness training for all employees and track completion rates.

    Why it's wrong here

    Annual training alone is insufficient for reducing phishing susceptibility. CIS Control 14 requires continuous, role-based training and simulated phishing exercises to reinforce skills. Simply tracking completion does not measure effectiveness or change behavior, and it fails to address the need for ongoing reinforcement and practical application.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.