Courseiva

CISM Information Security Programme Practice Question

Which TWO of the following are typical components of a security awareness program?

⚠ Common exam trap

CISM often tests the confusion between awareness program components and technical security controls — candidates may select vulnerability scanning or pen testing because they are security-related, but they are not awareness activities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Role-based security training

Role-based security training (A) is a core element of a security awareness program because it tailors education to the specific risks and responsibilities of different job functions, such as developers, finance staff, or executives, ensuring relevant and effective learning. Phishing simulations (C) are also typical, as they provide practical, measurable testing of employees' ability to recognize and report social-engineering attempts, reinforcing awareness training with real-world exercises. Vulnerability scanning (B) is a technical control that identifies weaknesses in systems and networks, not an awareness activity aimed at changing employee behavior. Security architecture design (D) is an engineering discipline focused on building secure systems, and penetration testing (E) is an offensive security assessment of technical controls, neither of which directly educates or measures the workforce.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Role-based security training

    Why this is correct

    Role-based security training tailors content to each group's specific responsibilities and risks, making it a standard component of an awareness programme. It satisfies the stem's requirement for typical components by addressing differentiated learning needs beyond generic annual instruction.

  • ✗

    Vulnerability scanning

    Why it's wrong here

    Vulnerability scanning identifies technical weaknesses in systems; awareness programmes change human behaviour through training, phishing simulations and communications. Scanning is tempting because it also reduces risk and often sits under the same security manager, but it belongs to vulnerability management, not to educating users about their responsibilities.

  • ✓

    Phishing simulations

    Why this is correct

    Phishing simulations test employees with realistic fraudulent emails and measure click and report rates, providing measurable behavioural evidence. This makes them a typical awareness programme component, satisfying the stem's requirement by reinforcing training through practical, repeatable exercises.

  • ✗

    Security architecture design

    Why it's wrong here

    Security architecture design produces the technical control framework that awareness training merely supports; it is an engineering activity, not an awareness component. It is tempting because architects do shape security posture, but awareness programmes target human behaviour through training, communications and phishing simulations, not topology or control selection.

  • ✗

    Penetration testing

    Why it's wrong here

    Penetration testing assesses technical controls by simulating attacks; it does not educate staff, which is the awareness programme's purpose. It is tempting because it falls under security assurance, but awareness components are things such as training, phishing simulations and policy acknowledgement.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.