easyMultiple Select
CISA Practice Question: Which TWO of the following are key components of…
Which TWO of the following are key components of an effective information security awareness program?
⚠ Common exam trap
It's easy for candidates to confuse operational security controls (like log reviews and vulnerability scans) with awareness program components, but the exam specifically tests the distinction between technical controls and human-focused training activities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mandatory training for all employees
Mandatory training for all employees (C) is a core component of an awareness program because it ensures every user receives consistent, documented instruction on policies, threats, and safe behaviors, which is the primary mechanism for changing human behavior. Phishing simulation exercises (E) are also essential because they provide realistic, measurable practice that reinforces training and identifies users who need additional coaching, directly testing the human layer that awareness programs target. By contrast, periodic review of security logs (A) and regular vulnerability scans (D) are technical security operations controls that detect and manage system weaknesses, not activities that educate or influence user behavior. An annual password change policy (B) is an authentication control or policy requirement; while it may be communicated through awareness efforts, the policy itself does not train or educate employees, so it is not a key component of an awareness program.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Periodic review of security logs
Why it's wrong here
Log review is a detective monitoring control performed by security staff, not an awareness component that educates users. It tempts because logging is central to security operations; it would be the correct answer to a question about monitoring or incident detection, not about building awareness.
- ✗
Annual password change policy
Why it's wrong here
A password change policy is a technical access control, not awareness activity; it changes no user behaviour or security understanding. It tempts because password hygiene is genuinely part of security programmes, but as an enforced system setting it would be the correct answer to a question about authentication controls, not awareness.
- ✓
Mandatory training for all employees
Why this is correct
Mandatory training ensures every employee receives consistent security instruction, satisfying the programme's need for universal coverage. Requiring completion, rather than offering optional sessions, closes the gap where untrained staff become the weakest link in controls.
- ✗
Regular vulnerability scans
Why it's wrong here
Vulnerability scanning is a technical assessment control that identifies weaknesses in systems, not a mechanism for changing user security behaviour. It tempts because scanning underpins many security programmes; it would be the correct answer to a question about vulnerability management or technical testing, not awareness.
- ✓
Phishing simulation exercises
Why this is correct
Phishing simulation exercises provide measurable behavioural evidence of susceptibility, satisfying the stem's requirement for an effective programme component. Unlike passive awareness materials, simulations test whether staff actually apply training, revealing click and reporting rates that inform targeted remediation. This active testing mechanism converts awareness from assumption into verified, trackable competence.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.