ISC2-CC - Security Operations (18% of the exam) - Section 5.3

Understand security awareness training and common security policies, including acceptable use, change management, and the role of logging and monitoring.

Recognise security awareness training as the control that addresses the human element - phishing recognition, social engineering, and password hygiene - and the common policies that govern behaviour, including acceptable use (AUP), change management, and data handling. Understand that logging and monitoring provide the audit trail that detects and reconstructs security events.

Security awareness trainingAcceptable use policyChange managementLogging and monitoringSocial engineering

Practice question for this objective

Free sampleSecurity Operationseasy

During onboarding at Jarrah Consulting, the security lead wants new hires to recognise phishing emails, choose strong passphrases, and understand how to report suspicious activity. Which programme is designed to deliver this understanding across the general workforce?

  • AA penetration testing engagement in which specialists attempt to breach systems to find exploitable weaknesses
  • BA vulnerability management process that scans systems and prioritises the flaws that need patching
  • CA security awareness training programme that educates all staff on recognising and responding to everyday threats Correct
  • DA disaster recovery exercise that rehearses restoring critical systems and data after a serious outage
Security awareness training educates the general workforce to recognise and respond to common threats such as phishing. Awareness training is aimed at every employee and builds the everyday habits, from spotting phishing to reporting, that reduce human-driven risk across the organisation.

Why A is wrong: Penetration testing probes technical defences and is performed by specialists, so it does not educate general staff about everyday threats such as phishing.

Why B is wrong: Vulnerability management identifies and remediates technical weaknesses in systems, not the human behaviours that awareness training is meant to shape.

Why C is correct: Security awareness training targets the whole workforce and covers recognising phishing, good password habits, and reporting, matching exactly what the lead wants delivered.

Why D is wrong: A disaster recovery exercise practises recovering operations after disruption, which is valuable but does not teach staff to spot phishing or choose passphrases.

See more ISC2-CC practice questions, answers explained.

Exam traps in Security Operations

Answers that look right on this material and are not. Each one is a distractor from a different question in the ISC2-CC bank for this domain.

  • To generate the tamper-evident audit trail that investigators rely on after a suspected breach.

    Why it is wrong: An audit trail is produced by logging, not by training. It is a tempting choice because both support security operations, but training changes behaviour rather than recording events.

  • They are the same, since both documents list the passwords and encryption keys used across the organisation.

    Why it is wrong: Neither document catalogues passwords or keys, and treating them as identical repeats the analyst's error. It is a giveaway that the statement endorses rather than corrects the misconception.

  • A distributed denial-of-service attack that floods the help desk line with automated calls until it becomes unavailable

    Why it is wrong: A denial-of-service attack targets availability of a service, not the human disclosure of credentials, so it does not match a caller persuading a person to reveal a password.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.