CISM Information Security Programme Practice Question
An information security manager is designing a security awareness program. Which approach BEST addresses the different learning needs of various employee groups?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deliver role-based training: secure coding for developers, social engineering for executives, and basic awareness for all
Role-based training ensures that each group receives content relevant to their responsibilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use only phishing simulations as training
Why it's wrong here
Phishing simulations test email vigilance only; they cannot address varied learning needs such as secure coding for developers or physical security for facilities staff. It is tempting because simulations provide measurable metrics and realistic practise, and they suit organisations needing to benchmark click rates — but a single format cannot cover diverse employee groups.
- ✗
Focus training only on high-risk groups such as system administrators
Why it's wrong here
Focusing solely on system administrators leaves general staff untrained, so the varied learning needs across all employee groups remain unaddressed. Targeting privileged users suits role-specific technical hardening, yet awareness programmes must reach every employee, since most breaches exploit ordinary users through phishing and social engineering.
- ✗
Provide the same annual training to all employees to ensure consistency
Why it's wrong here
Uniform annual training ignores differing roles, risk exposure and learning preferences, so it fails to address varied needs. It is tempting because consistency simplifies delivery, tracking and compliance evidence, and it suits organisations with homogeneous, low-risk populations — but tailoring by role and format is required when employee groups differ.
- ✓
Deliver role-based training: secure coding for developers, social engineering for executives, and basic awareness for all
Why this is correct
Role-based delivery matches content to each group's actual risk exposure: developers need secure coding, executives need social engineering awareness, and everyone needs baseline awareness. This satisfies the stem's constraint of addressing differing learning needs across employee groups simultaneously.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.