Courseiva
Information Security ProgramhardMultiple ChoiceObjective-mapped

CISM Information Security Program Practice Question

A large healthcare organization recently experienced a ransomware attack that encrypted patient records (ePHI). The attack originated from a phishing email that bypassed the email security gateway. The security program includes annual security awareness training, but post-incident analysis reveals that employees often ignore suspicious emails. The CISO wants to revise the program to reduce the likelihood of similar incidents. Which course of action is most effective?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Increase the frequency of phishing simulations and enforce mandatory remedial training for employees who fall for them

Most effective because it directly addresses the human factor by increasing the frequency of phishing simulations and providing remedial training, which reinforces secure behavior. Option A improves technology but does not change employee behavior. Option B (next-generation email security gateway) may help block some phishing emails but does not address the root cause of employees ignoring suspicious emails. Option C (EDR) can detect ransomware after execution but does not prevent the initial phishing compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Restrict users' ability to receive emails from external domains except from approved senders

    Why it's wrong here

    This is too restrictive and may disrupt legitimate business communication.

  • Implement a next-generation email security gateway with AI-based threat detection

    Why it's wrong here

    This improves detection but does not address the behavioral root cause.

  • Deploy endpoint detection and response (EDR) on all workstations

    Why it's wrong here

    EDR provides post-compromise detection but does not prevent the initial infection.

  • Increase the frequency of phishing simulations and enforce mandatory remedial training for employees who fall for them

    Why this is correct

    This directly modifies employee behavior through repeated testing and education.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.