mediumMultiple Choice
CISSP Is implementing a security awareness program Practice Question
An organization is implementing a security awareness program. Which topic should be emphasized most?
⚠ Common exam trap
ISC2 often tests the concept that while all options are valid security awareness topics, phishing recognition is the highest priority because it directly counters the most prevalent and successful attack vector, not because the other topics are unimportant.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing recognition
Phishing recognition is the most critical topic because phishing attacks are the primary vector for initial access in over 90% of security breaches, according to Verizon's DBIR. Unlike other topics, phishing directly exploits human psychology to bypass technical controls like email filters and MFA, making user detection the last line of defense. Emphasizing this topic reduces the risk of credential theft, malware installation, and ransomware deployment more effectively than any other single awareness area.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Social media usage
Why it's wrong here
Social media usage covers oversharing and reputation, but it does not address phishing, pretexting or tailgating, the people-focused threats an awareness programme targets. It would be the emphasis where the assessed risk is information leakage through public posts or recruitment-based reconnaissance.
- ✓
Phishing recognition
Why this is correct
Phishing remains the dominant initial-access vector, exploiting human judgement rather than technical flaws, so recognition training yields the greatest risk reduction. Emphasising it satisfies the programme's goal of addressing the most probable and impactful threat to the organisation.
- ✗
Password policy
Why it's wrong here
Password policy teaches credential construction, yet users following it still surrender credentials to phishing and social engineering, the dominant initial-access vector awareness addresses. It would be the emphasis where weak or reused credentials are the identified risk, such as after a credential-stuffing incident.
- ✗
Clean desk policy
Why it's wrong here
A clean desk policy addresses physical document and media exposure, which awareness training covers but which does not counter the human-targeted attacks, such as phishing and social engineering, that awareness programmes primarily exist to reduce. It would be the emphasis where physical snooping or unattended sensitive material is the assessed risk.
Go deeper
Related to this question
Learn chapter
Access Control Models and Mechanisms
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.