Courseiva

CISM Information Security Programme Practice Question

In a security awareness program, which training approach is most appropriate for software developers?

⚠ Common exam trap

CISM often tests audience-appropriateness — candidates pick generic phishing awareness because it is the most familiar training, missing that developers require secure coding content specific to their role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Secure coding practices and common vulnerabilities

Software developers need role-specific training on secure coding practices and common vulnerabilities such as OWASP Top 10 issues, injection flaws, and insecure deserialization, because they directly write and maintain code that introduces or prevents these flaws. Generic awareness training does not address their actual responsibilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Secure coding practices and common vulnerabilities

    Why this is correct

    Developers introduce vulnerabilities through code, so secure coding practices and common vulnerabilities (for example injection or insecure deserialisation) target the exact skills their role demands. Generic awareness content would not address the technical mechanisms they must apply daily.

  • ✗

    Social engineering awareness for executives

    Why it's wrong here

    Social engineering awareness for executives targets leadership targeting and business email compromise, not the secure development lifecycle skills developers require. It is tempting because it is the correct choice for senior management, who face whaling and pretexting attacks and authorise high-value transactions.

  • ✗

    Incident response procedures

    Why it's wrong here

    Incident response procedures teach reaction after a compromise, whereas developers need preventive secure coding practise to avoid introducing vulnerabilities in the first place. It is tempting because it is the correct training for the security operations team who handle and contain detected incidents.

  • ✗

    General security awareness training covering phishing

    Why it's wrong here

    Generic phishing awareness addresses broad employee behaviour, not the coding flaws developers introduce, such as injection or insecure deserialisation, so it misses their role-specific risk. It is tempting because it is the correct choice for the general workforce, where phishing remains the dominant initial access vector.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.