Valid CRISC Dumps shared by ExamDiscuss.com for Helping Passing CRISC Exam! ExamDiscuss.com now offer the newest CRISC exam dumps, the ExamDiscuss.com CRISC exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com CRISC dumps with Test Engine here:
An organization recently implemented a cybersecurity awareness program that includes phishing simulation exercises for all employees. What type of control is being utilized?
Correct Answer: C
Implementing a cybersecurity awareness program that includes phishing simulation exercises is an example of a deterrent control. Deterrent Control: Definition: Deterrent controls are designed to discourage individuals from performing undesirable activities by making them aware of the consequences or increasing the perceived risk of detection. Phishing Simulations: By conducting phishing simulations, employees are made aware of phishing threats and are educated on recognizing and avoiding such attacks. This reduces the likelihood of them falling victim to real phishing attempts. Purpose and Impact: Behavioral Change: The primary goal is to change the behavior of employees, making them more vigilant and less likely to engage with phishing emails. Awareness and Training: These simulations act as a continuous training tool, reinforcing the importance of cybersecurity and deterring careless actions. References: The CISM Review Manual and various cybersecurity guidelines highlight phishing simulations as an effective deterrent control to enhance employee awareness and reduce the risk of successful phishing attacks .