ISC2-CC - Security Operations - Section 5.3

Understand security awareness training and common security policies, including acceptable use, change management, and the role of logging and monitoring.

Recognise security awareness training as the control that addresses the human element - phishing recognition, social engineering, and password hygiene - and the common policies that govern behaviour, including acceptable use (AUP), change management, and data handling. Understand that logging and monitoring provide the audit trail that detects and reconstructs security events.

Security awareness trainingAcceptable use policyChange managementLogging and monitoringSocial engineering

Practice question for this objective

Free sampleSecurity Operationseasy

During onboarding at Jarrah Consulting, the security lead wants new hires to recognise phishing emails, choose strong passphrases, and understand how to report suspicious activity. Which programme is designed to deliver this understanding across the general workforce?

  • AA penetration testing engagement in which specialists attempt to breach systems to find exploitable weaknesses
  • BA vulnerability management process that scans systems and prioritises the flaws that need patching
  • CA security awareness training programme that educates all staff on recognising and responding to everyday threats Correct
  • DA disaster recovery exercise that rehearses restoring critical systems and data after a serious outage
Security awareness training educates the general workforce to recognise and respond to common threats such as phishing. Awareness training is aimed at every employee and builds the everyday habits, from spotting phishing to reporting, that reduce human-driven risk across the organisation.

Why A is wrong: Penetration testing probes technical defences and is performed by specialists, so it does not educate general staff about everyday threats such as phishing.

Why B is wrong: Vulnerability management identifies and remediates technical weaknesses in systems, not the human behaviours that awareness training is meant to shape.

Why C is correct: Security awareness training targets the whole workforce and covers recognising phishing, good password habits, and reporting, matching exactly what the lead wants delivered.

Why D is wrong: A disaster recovery exercise practises recovering operations after disruption, which is valuable but does not teach staff to spot phishing or choose passphrases.

See more ISC2-CC practice questions with worked answers.

More in this domain

Back to all Security Operations objectives, or the ISC2-CC cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.