nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #595

Which of the following is a best practice for security awareness training?

The correct answer is D. Making training sessions mandatory for all employees. Making security awareness training mandatory ensures consistent coverage across the entire organization, reducing the human risk surface. Option A (once a year only) is insufficient given the evolving threat landscape - best practice calls for continuous or periodic training…

Security Principles

Question

Which of the following is a best practice for security awareness training?

Options

  • AProviding training only once a year
  • BNone of the above
  • CProviding the same training to all employees
  • DMaking training sessions mandatory for all employees

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    4% (1)
  • C
    4% (1)
  • D
    86% (24)

Explanation

Making security awareness training mandatory ensures consistent coverage across the entire organization, reducing the human risk surface. Option A (once a year only) is insufficient given the evolving threat landscape - best practice calls for continuous or periodic training. Option C (same training for all) is also not ideal because different roles carry different risks and responsibilities; role-based training is more effective. Mandatory, role-appropriate, and regularly updated training is the recognized best practice.

Topics

#Security Awareness Training#Best Practices#Human Factors#Cybersecurity Education

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice