Courseiva

CISM Information Security Programme Practice Question

Which of the following is the PRIMARY purpose of a security champions program?

⚠ Common exam trap

CISM often tests the difference between a security champions program and other security functions; candidates may confuse it with enforcement or incident response, but the key is 'embedding' security advocates in development teams.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Embed security advocates in dev teams to promote secure practices

The primary purpose of a security champions program is to embed security advocates within development teams to promote secure practices and foster a security culture. Champions are developers who receive additional security training and act as the go-to person for security questions within their team, helping to integrate security earlier in the SDLC. This scales security knowledge without adding dedicated security staff to every team.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enforce compliance with security policies

    Why it's wrong here

    Enforcing policy compliance is a control and audit function, not the champions program's aim. Champions are embedded advocates who influence secure design and raise security awareness within their teams. It is tempting because champions do encourage adherence, and would be correct if the objective were monitoring or policing compliance.

  • ✓

    Embed security advocates in dev teams to promote secure practices

    Why this is correct

    Champions sit inside development teams, so security guidance reaches code as it is written rather than after release. This satisfies the stem's primary purpose: advocacy embedded at the source, shifting security left and building a culture of shared ownership rather than centralised enforcement.

  • ✗

    Reduce the number of phishing simulations

    Why it's wrong here

    Reducing phishing simulations confuses an awareness metric with the program's purpose. Security champions embed security practise within development teams, extending the security function's reach. It is tempting because champions do promote secure behaviour, and would be relevant if the goal were improving phishing resilience specifically.

  • ✗

    Replace the need for a dedicated security team

    Why it's wrong here

    Champions supplement rather than replace a dedicated security team, which retains accountability and specialist expertise. The program's purpose is extending security influence into delivery teams. It is tempting because champions do absorb routine security tasks, and would be relevant when scaling security capacity without proportional headcount growth.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.