Courseiva

CISM Information Security Programme Practice Question

An organization is implementing a security champions program. What is the primary purpose of this initiative?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To embed security advocates within development teams to improve secure coding practices

Security champions embed security advocates within development teams to promote secure practices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    To embed security advocates within development teams to improve secure coding practices

    Why this is correct

    Security champions are developers who remain embedded in their teams while receiving extra security training, so secure coding practises are applied during development rather than retrofitted. This distributes security expertise into delivery teams, satisfying the aim of improving secure coding at source.

  • ✗

    To conduct security awareness training for all employees

    Why it's wrong here

    Champions receive deeper, role-specific enablement and then embed secure practises in their teams; organisation-wide awareness training is delivered separately to every employee. It is tempting because champions do raise awareness locally, but the programme targets a selected cohort rather than the whole workforce, so it cannot be the primary purpose.

  • ✗

    To provide a career path for security professionals

    Why it's wrong here

    The programme builds a network of non-security staff who champion secure practises within their own teams; it is not a progression framework, and champions typically remain in their primary roles. It is tempting because participation can enhance a CV, but career development is a by-product, not the initiative's primary purpose.

  • ✗

    To replace the need for a dedicated security team

    Why it's wrong here

    Security champions are embedded advocates who extend the security team's reach into development and business units; they supplement rather than replace dedicated specialists, who retain ownership of policy, architecture and incident response. The option is tempting because champions do absorb some triage and awareness duties, but eliminating the security function removes the expertise the programme depends on.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.