Courseiva

CISM Information Security Programme Practice Question

A company is designing a security awareness program. Which approach is MOST effective for ensuring that employees apply security principles in their daily work?

⚠ Common exam trap

CISM often tests the misconception that a one-size-fits-all annual training is sufficient, when in fact role-based, continuous training is more effective for behavior change.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Role-based training: developers receive secure coding training, executives receive social engineering awareness

Role-based training is most effective because it tailors security education to the specific risks and responsibilities of different job functions. Developers need secure coding practices, while executives are prime targets for social engineering. This relevance increases engagement and application of security principles in daily work. Other approaches are either too generic or lack the necessary depth.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Annual computer-based training for all employees covering general security topics

    Why it's wrong here

    Annual computer-based training delivers generic content once a year, disconnected from employees' actual roles and daily tasks. It is tempting because it is auditable and scales cheaply, and it would satisfy a compliance evidence requirement rather than changing on-the-job behaviour.

  • ✓

    Role-based training: developers receive secure coding training, executives receive social engineering awareness

    Why this is correct

    Tailoring content to each role's actual tasks ensures relevance, so developers learn secure coding for the code they write and executives recognise social engineering targeting them. This role-specific alignment drives daily application of security principles better than generic awareness content.

  • ✗

    Monthly phishing simulations without any accompanying training

    Why it's wrong here

    Simulations alone measure click rates without teaching correct handling, so staff learn to recognise the test rather than the threat. Simulations are tempting because they give measurable metrics, and they work well when paired with immediate teachable-moment feedback after each failure.

  • ✗

    A one-time security awareness seminar conducted by an external consultant

    Why it's wrong here

    A single seminar produces a one-off knowledge spike with no reinforcement, so behaviour decays quickly. It is tempting because external consultants appear authoritative and the format is easy to schedule, but it would suit introducing a brand-new topic rather than embedding daily habits.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.