Courseiva
mediumMultiple Choice

CISSP Is implementing a security awareness program Practice Question

An organization is implementing a security awareness program. Which topic should be emphasized most?

⚠ Common exam trap

ISC2 often tests the concept that while all options are valid security awareness topics, phishing recognition is the highest priority because it directly counters the most prevalent and successful attack vector, not because the other topics are unimportant.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing recognition

Phishing recognition is the most critical topic because phishing attacks are the primary vector for initial access in over 90% of security breaches, according to Verizon's DBIR. Unlike other topics, phishing directly exploits human psychology to bypass technical controls like email filters and MFA, making user detection the last line of defense. Emphasizing this topic reduces the risk of credential theft, malware installation, and ransomware deployment more effectively than any other single awareness area.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Social media usage

    Why it's wrong here

    Social media usage covers oversharing and reputation, but it does not address phishing, pretexting or tailgating, the people-focused threats an awareness programme targets. It would be the emphasis where the assessed risk is information leakage through public posts or recruitment-based reconnaissance.

  • ✓

    Phishing recognition

    Why this is correct

    Phishing remains the dominant initial-access vector, exploiting human judgement rather than technical flaws, so recognition training yields the greatest risk reduction. Emphasising it satisfies the programme's goal of addressing the most probable and impactful threat to the organisation.

  • ✗

    Password policy

    Why it's wrong here

    Password policy teaches credential construction, yet users following it still surrender credentials to phishing and social engineering, the dominant initial-access vector awareness addresses. It would be the emphasis where weak or reused credentials are the identified risk, such as after a credential-stuffing incident.

  • ✗

    Clean desk policy

    Why it's wrong here

    A clean desk policy addresses physical document and media exposure, which awareness training covers but which does not counter the human-targeted attacks, such as phishing and social engineering, that awareness programmes primarily exist to reduce. It would be the emphasis where physical snooping or unattended sensitive material is the assessed risk.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.