nerdexam
Isaca

CISM · Question #726

The PRIMARY objective of an organization-wide information security awareness and training program is to:

The correct answer is B. improve employee security behaviors. The primary objective of a security awareness and training program is to change and improve employee security behaviors - making people less likely to fall for phishing, mishandle data, or bypass controls. No program can prevent all incidents (A), making that choice…

Submitted by andreas_gr· Apr 18, 2026Information Security Program

Question

The PRIMARY objective of an organization-wide information security awareness and training program is to:

Options

  • Aprevent all security incidents from occurring.
  • Bimprove employee security behaviors.
  • Callocate information security resources more efficiently.
  • Dmeet regulatory requirements.

How the community answered

(38 responses)
  • B
    92% (35)
  • C
    3% (1)
  • D
    5% (2)

Explanation

The primary objective of a security awareness and training program is to change and improve employee security behaviors - making people less likely to fall for phishing, mishandle data, or bypass controls. No program can prevent all incidents (A), making that choice unrealistic. Resource efficiency (C) and regulatory compliance (D) may be secondary benefits, but they are not the driving purpose. Behavior change is the mechanism through which all other benefits flow, making it the correct primary objective.

Topics

#Security Awareness#Security Training#Employee Behavior#Information Security Program Objectives

Community Discussion

No community discussion yet for this question.

Full CISM Practice