CISM Information Security Programme Practice Question
A company is designing a security awareness program. Which approach is MOST effective for ensuring that employees apply security principles in their daily work?
⚠ Common exam trap
CISM often tests the misconception that a one-size-fits-all annual training is sufficient, when in fact role-based, continuous training is more effective for behavior change.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role-based training: developers receive secure coding training, executives receive social engineering awareness
Role-based training is most effective because it tailors security education to the specific risks and responsibilities of different job functions. Developers need secure coding practices, while executives are prime targets for social engineering. This relevance increases engagement and application of security principles in daily work. Other approaches are either too generic or lack the necessary depth.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Annual computer-based training for all employees covering general security topics
Why it's wrong here
Annual computer-based training delivers generic content once a year, disconnected from employees' actual roles and daily tasks. It is tempting because it is auditable and scales cheaply, and it would satisfy a compliance evidence requirement rather than changing on-the-job behaviour.
- ✓
Role-based training: developers receive secure coding training, executives receive social engineering awareness
Why this is correct
Tailoring content to each role's actual tasks ensures relevance, so developers learn secure coding for the code they write and executives recognise social engineering targeting them. This role-specific alignment drives daily application of security principles better than generic awareness content.
- ✗
Monthly phishing simulations without any accompanying training
Why it's wrong here
Simulations alone measure click rates without teaching correct handling, so staff learn to recognise the test rather than the threat. Simulations are tempting because they give measurable metrics, and they work well when paired with immediate teachable-moment feedback after each failure.
- ✗
A one-time security awareness seminar conducted by an external consultant
Why it's wrong here
A single seminar produces a one-off knowledge spike with no reinforcement, so behaviour decays quickly. It is tempting because external consultants appear authoritative and the format is easy to schedule, but it would suit introducing a brand-new topic rather than embedding daily habits.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.