CISA Protection of Information Assets Practice Question
An IS auditor is evaluating the effectiveness of a security awareness program. Which of the following metrics would BEST indicate that the program is achieving its objectives?
⚠ Common exam trap
CISA often tests the difference between output metrics (e.g., completion rates, quiz scores) and outcome metrics (e.g., reduction in successful attacks). Candidates may mistakenly select completion rates or quiz scores as they are easy to measure, but the exam expects the metric that best indicates achievement of objectives, which is behavioral change.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reduction in the number of successful phishing attacks
The primary objective of a security awareness program is to change employee behavior to reduce security risks. A reduction in successful phishing attacks directly measures whether employees are applying what they learned to avoid real-world threats, making it the best outcome-based metric. Post-training quiz scores, completion rates, and incident reporting numbers are activity or output metrics that do not necessarily reflect actual behavioral change or risk reduction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Scores on post-training quizzes
Why it's wrong here
Quiz scores measure short-term knowledge retention immediately after training, not sustained security behaviour or reduced risk, which is what the programme's objectives target. Quizzes are tempting because they are quantifiable and simple to administer. They would be the correct metric when assessing whether employees understood the training content itself.
- ✓
Reduction in the number of successful phishing attacks
Why this is correct
Awareness programmes aim to change behaviour, so fewer successful phishing attacks demonstrates that staff actually recognise and resist real threats. This outcome metric reflects genuine risk reduction, unlike completion rates or quiz scores, which measure attendance rather than effectiveness.
- ✗
Percentage of employees who completed the annual training
Why it's wrong here
Completion counts measure attendance and administrative compliance, not whether behaviour or knowledge changed, so they cannot evidence the programme's objectives. Completion tracking is tempting because it is easy to collect and report. It would be the right metric for demonstrating training coverage or regulatory compliance rather than awareness effectiveness.
- ✗
Number of security incidents reported by employees
Why it's wrong here
Reported incident counts measure employee willingness to report, which can rise as awareness improves, but also reflect incident volume, phishing attempts and reporting culture, so they do not isolate programme effectiveness. Reporting metrics are tempting because they suggest engagement. They would be correct when evaluating the detection or reporting channel itself.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.