CISM Information Security Programme Practice Question
A security manager is designing a security awareness program for a mid-sized organization. Which of the following is the MOST effective approach to ensure that training is relevant to different employee roles?
⚠ Common exam trap
CISM often tests the misconception that consistency (same training for everyone) equals effectiveness, or that simulations alone constitute a training program, when role relevance and formal instruction are the key differentiators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide role-based training that addresses specific risks for each job function.
Role-based training is the most effective approach because it tailors content to the specific risks, tools, and data each job function handles, increasing relevance and retention. For example, finance staff need payment fraud and invoice manipulation training, while developers need secure coding and secrets management. This targeted approach addresses the actual threat surface of each role rather than delivering generic content.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deliver the same annual training to all employees to ensure consistency.
Why it's wrong here
Identical annual content cannot address the differing threats each role faces, such as finance handling invoice fraud versus developers managing code repositories, so relevance is lost. Uniform delivery is tempting because it is administratively simple and ensures consistent baseline coverage, which suits small organisations with homogeneous duties.
- ✓
Provide role-based training that addresses specific risks for each job function.
Why this is correct
Role-based training maps controls and threats to each function's actual workflows, so relevance is achieved by addressing the specific risks that job holders face. This satisfies the requirement for differentiated relevance across employee roles rather than generic, one-size-fits-all content.
- ✗
Focus only on senior executives since they are the primary targets of social engineering.
Why it's wrong here
Restricting training to executives leaves the majority of staff unequipped to recognise social engineering, so role-relevant coverage fails for the wider workforce. It is tempting because executives are high-value targets, and executive-specific briefings are valid as one component within a layered programme, not as the whole approach.
- ✗
Conduct quarterly phishing simulations without any formal training.
Why it's wrong here
Simulations test whether existing knowledge is applied; without formal instruction, staff who fail receive no teaching of correct behaviours, so relevance across roles is never established. Simulations are tempting because they measure click rates and reinforce habits, and they work well once baseline role-based training has already been delivered.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.