nerdexam
Isaca

CISM · Question #900

Which of the following is the MOST effective way to help ensure web developers understand the growing severity of web application security risks?

The correct answer is C. Implement a tailored security awareness training program. The question focuses on helping developers understand - a learning and awareness objective. A tailored security awareness training program directly addresses knowledge and comprehension, and because it is tailored to developers, it uses relevant examples, realistic attack…

Submitted by jian89· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is the MOST effective way to help ensure web developers understand the growing severity of web application security risks?

Options

  • AIntegrate security into the early phases of the development life cycle.
  • BIncorporate security requirements into job descriptions.
  • CImplement a tailored security awareness training program.
  • DStandardize secure web development practices.

How the community answered

(21 responses)
  • A
    10% (2)
  • B
    5% (1)
  • C
    81% (17)
  • D
    5% (1)

Explanation

The question focuses on helping developers understand - a learning and awareness objective. A tailored security awareness training program directly addresses knowledge and comprehension, and because it is tailored to developers, it uses relevant examples, realistic attack scenarios, and role-specific content that resonates with their work. Integrating security into the SDLC (A) embeds process controls but does not necessarily build understanding. Job description requirements (B) set expectations but do not teach. Standardizing practices (D) enforces behavior but does not build comprehension. Only targeted training directly develops understanding of why risks are growing and what they mean.

Topics

#Security Awareness#Training#Web Application Security#Software Development Security

Community Discussion

No community discussion yet for this question.

Full CISM Practice