nerdexam
Isaca

CISM · Question #681

An organization dealing with an increased number of successful phishing attacks has requested that the information security manager take action to address the problem. Which of the following would…

The correct answer is D. Assess the current information security awareness of staff. Assessing the current awareness of staff helps identify knowledge gaps that contribute to successful phishing attacks, allowing for targeted training and awareness programs to effectively reduce user susceptibility.

Submitted by paula_co· Apr 18, 2026Information Security Program Development and Management

Question

An organization dealing with an increased number of successful phishing attacks has requested that the information security manager take action to address the problem. Which of the following would be the MOST effective strategy?

Options

  • AIsolate offending domains that send malicious emails.
  • BConduct regular reviews of email spam filtering.
  • CUpdate security policies with consequences for noncompliance.
  • DAssess the current information security awareness of staff.

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    11% (4)
  • C
    29% (11)
  • D
    55% (21)

Explanation

Assessing the current awareness of staff helps identify knowledge gaps that contribute to successful phishing attacks, allowing for targeted training and awareness programs to effectively reduce user susceptibility.

Topics

#Security Awareness#Phishing Mitigation#Human Factors#Security Program Effectiveness

Community Discussion

No community discussion yet for this question.

Full CISM Practice