nerdexam
Isaca

CISM · Question #672

An organization identified a security breach resulting from an employee clicking on a malicious link within an email and failing to report it. Which of the following would BEST enable the…

The correct answer is A. Conduct regular simulated phishing exercises. Simulated phishing exercises improve employee awareness and preparedness by training them to recognize and report malicious emails, enhancing the organization’s ability to detect and respond to incidents early.

Submitted by ahmad_uae· Apr 18, 2026Information Security Incident Management

Question

An organization identified a security breach resulting from an employee clicking on a malicious link within an email and failing to report it. Which of the following would BEST enable the organization to improve incident detection and reporting?

Options

  • AConduct regular simulated phishing exercises
  • BIncrease penalties for employees who become victims of phishing attacks
  • CImplement AI-based email message scanning tools to filter malicious messages
  • DMonitor employee emails for suspicious activity

How the community answered

(30 responses)
  • A
    63% (19)
  • B
    7% (2)
  • C
    20% (6)
  • D
    10% (3)

Explanation

Simulated phishing exercises improve employee awareness and preparedness by training them to recognize and report malicious emails, enhancing the organization’s ability to detect and respond to incidents early.

Topics

#Phishing awareness#Security awareness training#Incident reporting#Incident detection

Community Discussion

No community discussion yet for this question.

Full CISM Practice