Courseiva

CISM Information Security Program Practice Question

An organization's security program has been in place for two years, but recently several security incidents occurred due to lack of user awareness. What is the most likely root cause?

⚠ Common exam trap

Test-takers frequently assume any security program automatically includes an effective awareness component, but CISM emphasizes that programs must be evaluated and updated regularly; a static program is as ineffective as having none.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The awareness program is not regularly updated or evaluated for effectiveness.

The scenario states the security program has been in place for two years, yet incidents persist due to lack of user awareness. This indicates the awareness program exists but is not being regularly updated or evaluated for effectiveness, which is a common root cause in mature programs where content becomes stale and fails to address evolving threats like phishing or social engineering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The awareness program is not regularly updated or evaluated for effectiveness.

    Why this is correct

    Incidents persisting two years after programme launch point to a static awareness programme that is neither refreshed to reflect current threats nor measured for effectiveness. Without periodic evaluation and content updates, users retain outdated knowledge, so awareness fails despite the programme's existence.

  • ✗

    Lack of a security awareness program.

    Why it's wrong here

    Incidents from poor user awareness point to absent awareness training, not to a missing programme as the root cause. The option is tempting because a programme is the usual vehicle for awareness, but it would be the correct root cause only where no awareness activity exists at all, which the stem does not establish.

  • ✗

    Insufficient budget for security tools.

    Why it's wrong here

    Budget constraints affect tooling coverage, not whether staff recognise phishing or follow policy, and the incidents are explicitly attributed to user awareness. Tool funding would be the root cause where incidents trace to missing detection or prevention controls rather than human behaviour.

  • ✗

    Insufficient firewall rules.

    Why it's wrong here

    Firewall rules govern network traffic filtering, not user behaviour, so they cannot address incidents explicitly attributed to awareness gaps. Insufficient rules would be the root cause where incidents stem from unfiltered or misconfigured network paths, not from users' actions.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.