Courseiva
easyMultiple Select

CISA Practice Question: Which TWO of the following are key components of…

Which TWO of the following are key components of an effective information security awareness program?

⚠ Common exam trap

It's easy for candidates to confuse operational security controls (like log reviews and vulnerability scans) with awareness program components, but the exam specifically tests the distinction between technical controls and human-focused training activities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mandatory training for all employees

Mandatory training for all employees (C) is a core component of an awareness program because it ensures every user receives consistent, documented instruction on policies, threats, and safe behaviors, which is the primary mechanism for changing human behavior. Phishing simulation exercises (E) are also essential because they provide realistic, measurable practice that reinforces training and identifies users who need additional coaching, directly testing the human layer that awareness programs target. By contrast, periodic review of security logs (A) and regular vulnerability scans (D) are technical security operations controls that detect and manage system weaknesses, not activities that educate or influence user behavior. An annual password change policy (B) is an authentication control or policy requirement; while it may be communicated through awareness efforts, the policy itself does not train or educate employees, so it is not a key component of an awareness program.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Periodic review of security logs

    Why it's wrong here

    Log review is a detective monitoring control performed by security staff, not an awareness component that educates users. It tempts because logging is central to security operations; it would be the correct answer to a question about monitoring or incident detection, not about building awareness.

  • ✗

    Annual password change policy

    Why it's wrong here

    A password change policy is a technical access control, not awareness activity; it changes no user behaviour or security understanding. It tempts because password hygiene is genuinely part of security programmes, but as an enforced system setting it would be the correct answer to a question about authentication controls, not awareness.

  • ✓

    Mandatory training for all employees

    Why this is correct

    Mandatory training ensures every employee receives consistent security instruction, satisfying the programme's need for universal coverage. Requiring completion, rather than offering optional sessions, closes the gap where untrained staff become the weakest link in controls.

  • ✗

    Regular vulnerability scans

    Why it's wrong here

    Vulnerability scanning is a technical assessment control that identifies weaknesses in systems, not a mechanism for changing user security behaviour. It tempts because scanning underpins many security programmes; it would be the correct answer to a question about vulnerability management or technical testing, not awareness.

  • ✓

    Phishing simulation exercises

    Why this is correct

    Phishing simulation exercises provide measurable behavioural evidence of susceptibility, satisfying the stem's requirement for an effective programme component. Unlike passive awareness materials, simulations test whether staff actually apply training, revealing click and reporting rates that inform targeted remediation. This active testing mechanism converts awareness from assumption into verified, trackable competence.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.