nerdexam
Isaca

CRISC · Question #339

Which of the following is the MOST effective way to validate organizational awareness of cybersecurity risk?

The correct answer is C. Implementing mock phishing exercises. Implementing mock phishing exercises is the most effective way to validate organizational awareness of cybersecurity risk.

Submitted by viktor_hu· Apr 18, 2026IT Risk Assessment

Question

Which of the following is the MOST effective way to validate organizational awareness of cybersecurity risk?

Options

  • AConducting security awareness training
  • BUpdating the information security policy
  • CImplementing mock phishing exercises
  • DRequiring two-factor authentication

How the community answered

(24 responses)
  • A
    13% (3)
  • B
    21% (5)
  • C
    58% (14)
  • D
    8% (2)

Why each option

Implementing mock phishing exercises is the most effective way to validate organizational awareness of cybersecurity risk.

AConducting security awareness training

Conducting security awareness training is crucial for *imparting* knowledge, but it doesn't *validate* whether that knowledge has been retained and translated into appropriate behavior.

BUpdating the information security policy

Updating the information security policy defines organizational expectations but does not measure whether employees are aware of or adhering to those expectations in practice.

CImplementing mock phishing exercisesCorrect

Mock phishing exercises provide a practical, hands-on method to assess whether employees can recognize and correctly respond to common cyber threats in a controlled, simulated environment. This approach directly measures the effectiveness of security awareness training by observing actual behavior, identifying specific gaps in awareness, and allowing for targeted remediation and reinforcement.

DRequiring two-factor authentication

Requiring two-factor authentication is a technical control to enhance security, not a method to *validate* the level of organizational awareness of cybersecurity risks.

Concept tested: Cybersecurity awareness validation

Source: https://csrc.nist.gov/publications/detail/sp/800-50/rev-1/archive/2003-08-11

Topics

#Cybersecurity awareness#Risk validation#Phishing simulation#Security testing

Community Discussion

No community discussion yet for this question.

Full CRISC Practice