nerdexam
Isaca

CISM · Question #932

Who are the first line of defense against information security breaches?

The correct answer is C. End users. End users (C) are the first line of defense because they interact directly with systems, data, and potential threats every day - phishing emails, suspicious links, weak passwords, and social engineering attacks all pass through end users before any technical control can…

Submitted by joshua94· Apr 18, 2026Information Security Program Development and Management

Question

Who are the first line of defense against information security breaches?

Options

  • AInformation security managers
  • BChief technology officers (CTOs)
  • CEnd users
  • DSecurity administrators

How the community answered

(18 responses)
  • A
    6% (1)
  • C
    89% (16)
  • D
    6% (1)

Explanation

End users (C) are the first line of defense because they interact directly with systems, data, and potential threats every day - phishing emails, suspicious links, weak passwords, and social engineering attacks all pass through end users before any technical control can intervene. Their awareness and behavior determine whether a threat gains a foothold in the first place.

  • A (Information security managers) are wrong because they set policies and oversee programs - they respond to and govern security, but don't directly encounter threats at the point of entry.
  • B (CTOs) are wrong because they focus on technology strategy and business outcomes, not day-to-day threat interaction.
  • D (Security administrators) are wrong because they manage tools and infrastructure (firewalls, patches, access controls) - they're a critical technical layer, but they act after a user has already been exposed.

Memory tip: Think of it like a bank robbery - the teller (end user) is the first person the robber encounters, not the manager in the back office. Training that teller is your first and most critical defense.

Topics

#End user security#Security awareness#First line of defense

Community Discussion

No community discussion yet for this question.

Full CISM Practice