nerdexam
Isaca

CISM · Question #627

Which of the following is the MOST effective long-term method to educate users about the identification, reporting, and impact of malicious emails?

The correct answer is A. Simulated phishing campaigns. Simulated phishing campaigns (A) are behaviorally active: they place users in realistic scenarios, deliver immediate and personal feedback when a user makes an error, and allow organizations to track improvement trends over time. This creates lasting behavioral change because…

Submitted by valeria.br· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is the MOST effective long-term method to educate users about the identification, reporting, and impact of malicious emails?

Options

  • ASimulated phishing campaigns
  • BMonthly town hall meetings
  • CCorporate intranet postings
  • DPosters throughout the office

How the community answered

(35 responses)
  • A
    83% (29)
  • B
    3% (1)
  • C
    6% (2)
  • D
    9% (3)

Explanation

Simulated phishing campaigns (A) are behaviorally active: they place users in realistic scenarios, deliver immediate and personal feedback when a user makes an error, and allow organizations to track improvement trends over time. This creates lasting behavioral change because the learning is experiential rather than passive. Town hall meetings (B), intranet postings (C), and office posters (D) are passive methods that raise general awareness but do not develop or test the specific skills needed to identify and report phishing. Research in security awareness consistently shows that active, repeated simulation is the most effective long-term intervention.

Topics

#Security Awareness Training#Phishing#User Education#Security Program Effectiveness

Community Discussion

No community discussion yet for this question.

Full CISM Practice