CISM Information Security Programme Practice Question
A company is designing its security awareness program. Which approach BEST addresses the need for role-based training?
⚠ Common exam trap
CISM often tests the misconception that a single, comprehensive training program for all employees is sufficient, but role-based training is essential to address specific risks and responsibilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide secure coding training to developers and social engineering awareness to executives
Role-based training tailors security education to the specific risks and responsibilities of different job functions. Developers need secure coding practices to prevent vulnerabilities like SQL injection or XSS, while executives are prime targets for social engineering and need awareness of executive-specific threats like whaling and business email compromise. This approach ensures that training is relevant, engaging, and effective in mitigating the most pertinent risks for each group.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Focus only on phishing simulations for all staff
Why it's wrong here
Phishing simulations test one attack vector and apply identically to all staff, so they cannot deliver role-specific content for privileged or high-risk functions. They tempt because they are measurable and engaging. Role-based training instead tailors material to each role's distinct responsibilities and threat exposure.
- ✗
Deliver the same annual training to all employees
Why it's wrong here
Uniform annual training delivers identical content regardless of job function, so it cannot satisfy role-based requirements for privileged or high-risk roles. It tempts because it is easy to administer and satisfies baseline awareness. Role-based training instead tailors content to each group's specific responsibilities and risks.
- ✓
Provide secure coding training to developers and social engineering awareness to executives
Why this is correct
Tailoring content to each role's actual threat exposure ensures relevance: developers need secure coding practise against injection flaws, while executives face targeted social engineering and business email compromise. Generic training for all staff fails to address these distinct risk profiles.
- ✗
Create a single module covering all topics for everyone
Why it's wrong here
A single all-topics module gives every employee the same content, so it cannot differentiate by role or address role-specific risks. It tempts because it covers everything once and scales easily. Role-based training instead segments content by job function, privileging relevant threats and responsibilities for each group.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.