Courseiva

CISM Information Security Programme Practice Question

An information security manager is designing a security awareness program. Which approach BEST addresses the different learning needs of various employee groups?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deliver role-based training: secure coding for developers, social engineering for executives, and basic awareness for all

Role-based training ensures that each group receives content relevant to their responsibilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use only phishing simulations as training

    Why it's wrong here

    Phishing simulations test email vigilance only; they cannot address varied learning needs such as secure coding for developers or physical security for facilities staff. It is tempting because simulations provide measurable metrics and realistic practise, and they suit organisations needing to benchmark click rates — but a single format cannot cover diverse employee groups.

  • ✗

    Focus training only on high-risk groups such as system administrators

    Why it's wrong here

    Focusing solely on system administrators leaves general staff untrained, so the varied learning needs across all employee groups remain unaddressed. Targeting privileged users suits role-specific technical hardening, yet awareness programmes must reach every employee, since most breaches exploit ordinary users through phishing and social engineering.

  • ✗

    Provide the same annual training to all employees to ensure consistency

    Why it's wrong here

    Uniform annual training ignores differing roles, risk exposure and learning preferences, so it fails to address varied needs. It is tempting because consistency simplifies delivery, tracking and compliance evidence, and it suits organisations with homogeneous, low-risk populations — but tailoring by role and format is required when employee groups differ.

  • ✓

    Deliver role-based training: secure coding for developers, social engineering for executives, and basic awareness for all

    Why this is correct

    Role-based delivery matches content to each group's actual risk exposure: developers need secure coding, executives need social engineering awareness, and everyone needs baseline awareness. This satisfies the stem's constraint of addressing differing learning needs across employee groups simultaneously.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.