CISM Information Security Programme Practice Question
In a security awareness program, which training approach is most appropriate for software developers?
⚠ Common exam trap
CISM often tests audience-appropriateness — candidates pick generic phishing awareness because it is the most familiar training, missing that developers require secure coding content specific to their role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secure coding practices and common vulnerabilities
Software developers need role-specific training on secure coding practices and common vulnerabilities such as OWASP Top 10 issues, injection flaws, and insecure deserialization, because they directly write and maintain code that introduces or prevents these flaws. Generic awareness training does not address their actual responsibilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Secure coding practices and common vulnerabilities
Why this is correct
Developers introduce vulnerabilities through code, so secure coding practices and common vulnerabilities (for example injection or insecure deserialisation) target the exact skills their role demands. Generic awareness content would not address the technical mechanisms they must apply daily.
- ✗
Social engineering awareness for executives
Why it's wrong here
Social engineering awareness for executives targets leadership targeting and business email compromise, not the secure development lifecycle skills developers require. It is tempting because it is the correct choice for senior management, who face whaling and pretexting attacks and authorise high-value transactions.
- ✗
Incident response procedures
Why it's wrong here
Incident response procedures teach reaction after a compromise, whereas developers need preventive secure coding practise to avoid introducing vulnerabilities in the first place. It is tempting because it is the correct training for the security operations team who handle and contain detected incidents.
- ✗
General security awareness training covering phishing
Why it's wrong here
Generic phishing awareness addresses broad employee behaviour, not the coding flaws developers introduce, such as injection or insecure deserialisation, so it misses their role-specific risk. It is tempting because it is the correct choice for the general workforce, where phishing remains the dominant initial access vector.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.