exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 220 discussion

Actual exam question from Isaca's CISM
Question #: 220
Topic #: 1
[All CISM Questions]

Information security awareness programs are MOST effective when they are:

  • A. sponsored by senior management.
  • B. reinforced by computer-based training.
  • C. customized for each target audience.
  • D. conducted at employee orientation.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
vavofa5697
Highly Voted 1 year, 8 months ago
Selected Answer: A
It should be A, because senior management's endorsement of the program and its importance to the organization sends a clear message to employees about the significance of information security.
upvoted 8 times
[Removed]
1 year, 3 months ago
Endorsment ny management doesnt mean they're effective
upvoted 4 times
...
...
oluchecpoint
Most Recent 9 months ago
Selected Answer: C
C. customized for each target audience. Effective information security awareness programs should be tailored to the specific needs and characteristics of the target audience. Different groups within an organization may have varying levels of knowledge, responsibilities, and potential security risks. Customizing the program ensures that the content is relevant and relatable to the individuals receiving the training, making it more likely to be effective in raising awareness and promoting good security practices.
upvoted 2 times
...
Uncle_Lucifer
10 months, 2 weeks ago
Selected Answer: C
Whats going on here? The question asks for most effective. Endorsement vs tailored delivery of training? --> customized delivery is more effective. C is the most correct answer. Management endorsement is the first action, but it is not the best for effectiveness.
upvoted 2 times
...
POWNED
11 months, 1 week ago
Selected Answer: C
A training video with nothing but a poop emoji dancing for 30 min could be endorsed by senior management, is it effective....I will let you answer that. Answer is C
upvoted 2 times
...
Soleandheel
11 months, 1 week ago
What makes it challenging is that they decided to use the word "Sponsored instead of endorsed". If a program is endorsed and supported by senior management it's always better which would make A the best answer choice. However, the word used is "Sponsored" which is not necessarily a synonym of "endorsed" or "supported"....or one could argue it means the same thing. If you sponsor it, does it mean you endorse it? Technically yes!
upvoted 1 times
...
DonnyX
1 year ago
Selected Answer: A
MY 20yrs exp. tells me it's A.. nothing can be more than helpful by a tone on the top.. even provide customized training can not be the most effective, trust me. it must be A..
upvoted 2 times
...
oluchecpoint
1 year, 1 month ago
C. customized for each target audience. Effective information security awareness programs should be tailored to the specific needs and characteristics of the target audience. Different groups within an organization may have varying levels of knowledge, responsibilities, and potential security risks. Customizing the program ensures that the content is relevant and relatable to the individuals receiving the training, making it more likely to be effective in raising awareness and promoting good security practices.
upvoted 2 times
...
[Removed]
1 year, 2 months ago
Selected Answer: C
The ISACA's CISM Review Manual 15th Edition emphasizes the importance of customizing security awareness programs for different target audiences: "The success of the security awareness program depends on how well it is tailored to its audience. One-size-fits-all approaches are usually less effective. Different groups within the organization have different roles and responsibilities and, therefore, need to be made aware of different aspects of security."
upvoted 4 times
...
DavoA
1 year, 2 months ago
Selected Answer: C
Totally agree with albin_kurti - "Endorsment ny management doesnt mean they're effective"
upvoted 1 times
...
richck102
1 year, 4 months ago
A. sponsored by senior management.
upvoted 1 times
...
sedardna
1 year, 5 months ago
Selected Answer: C
Tengo mis dudas. Se supone que ya hay programa, luego la alta gerencia ya a demostrado su implicación .
upvoted 1 times
...
dark_3k03r
1 year, 5 months ago
Selected Answer: A
The correct answer is (A) sponsored by senior management. As sponsorship usually brings: Top-down support and endorsement of the program Allocation of sufficient resources (financial and human) for the program Integration of the program with the overall organizational goals and strategies - accountability and ownership for the success of the program - visibility and credibility for the program - Promotion of a culture of security awareness - Reinforcement of the importance as a business priority Rationale: (B.) reinforced by computer-based training is not correct cause it doesn't show the organization's commitment to the training (C.) customized for each target audience, this is incredibly important, but without the financial support, promotion, or enforcement of management sponsorship this won't get far. (D.) conducted at employee orientation, this is great, but not sufficient for the long-term value.
upvoted 1 times
...
User21
1 year, 5 months ago
Selected Answer: C
customised training plan makes it effective
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago