CISA - Protection of Information Assets (26% of the exam) - Section 5.2

Evaluate security awareness training and programs and information system attack methods and techniques.

Recognise the components of an effective security awareness training programme and how it reduces the risk of social engineering and human error. Distinguish common IS attack methods and techniques - such as phishing, ransomware and insider threats - and the threat actor categories associated with each.

security awareness trainingattack methodsattack techniquesthreat actors

Practice question for this objective

Free sampleProtection of Information Assetsmedium

An IS auditor is reviewing the design of a security awareness programme for a national insurer. Which characteristic BEST distinguishes a mature awareness programme from a one-off training campaign?

  • AAnnual computer-based training that all employees must complete by year-end to satisfy the regulator.
  • BContinuous reinforcement using role-tailored content, behavioural metrics, and content refreshed against the current threat landscape. Correct
  • CA signed acceptable-use policy collected from each new joiner during the onboarding induction session.
  • DA quarterly newsletter from the chief information security officer summarising recent incidents handled by the security operations centre.
Recognise that a mature security awareness programme is continuous, role-tailored, threat-driven, and measured by behavioural outcomes rather than completion rates. Awareness maturity models such as those described in NIST SP 800-50 and SANS Security Awareness Maturity Model treat awareness as a sustained behaviour-change programme. The key indicators are role tailoring, continuous reinforcement, threat-informed content updates, and quantitative behavioural metrics. Annual completion, policy signatures, or newsletters are inputs, not the programme itself, and none of them evidences behaviour change over time.

Why A is wrong: Annual mandatory training is a baseline regulatory floor and is tempting because most organisations satisfy compliance this way, but it is a point-in-time campaign rather than an ongoing programme tied to measurable behaviour change.

Why B is correct: Maturity in awareness is defined by sustained reinforcement, role-relevant content, behavioural metrics such as phishing click and report rates, and refresh cycles aligned to current threat intelligence rather than a single annual event.

Why C is wrong: Capturing a policy acknowledgement is a useful administrative control and looks like awareness, but a signature confirms receipt only and does nothing to reinforce behaviour, measure understanding, or evolve content with the threat landscape.

Why D is wrong: Executive newsletters provide visibility and are easy to confuse with reinforcement, yet a one-way bulletin neither tailors content to role-specific risk nor measures whether staff behaviour actually changes as a result.

See more CISA practice questions, answers explained.

Exam traps in Protection of Information Assets

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • Conclude that the awareness programme is effective because the completion rate exceeds the ninety-five per cent threshold set by management.

    Why it is wrong: Completion is an input metric, not an outcome metric. Concluding effectiveness from completion alone ignores the incident evidence that contradicts it, and is not a defensible audit conclusion.

  • Spear phishing, because the attacker had researched the partner and tailored the approach to a specific high-value identity within the firm.

    Why it is wrong: Spear phishing involves tailored electronic messages, usually email, aimed at a specific individual. The targeting is similar, but the attack here was delivered by voice call to the service desk, which is a different channel and a different defensive control set.

  • They are defined primarily by the use of zero-day exploits at every stage of every intrusion they conduct against a target organisation.

    Why it is wrong: Zero-day exploitation is often present in advanced persistent threat activity, but it is neither the defining feature nor uniformly used at every stage; many advanced persistent threat intrusions rely on commodity malware once initial access is gained.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.