Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is evaluating the effectiveness of a security awareness program. Which of the following metrics would BEST indicate that the program is achieving its objectives?

⚠ Common exam trap

CISA often tests the difference between output metrics (e.g., completion rates, quiz scores) and outcome metrics (e.g., reduction in successful attacks). Candidates may mistakenly select completion rates or quiz scores as they are easy to measure, but the exam expects the metric that best indicates achievement of objectives, which is behavioral change.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reduction in the number of successful phishing attacks

The primary objective of a security awareness program is to change employee behavior to reduce security risks. A reduction in successful phishing attacks directly measures whether employees are applying what they learned to avoid real-world threats, making it the best outcome-based metric. Post-training quiz scores, completion rates, and incident reporting numbers are activity or output metrics that do not necessarily reflect actual behavioral change or risk reduction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Scores on post-training quizzes

    Why it's wrong here

    Quiz scores measure short-term knowledge retention immediately after training, not sustained security behaviour or reduced risk, which is what the programme's objectives target. Quizzes are tempting because they are quantifiable and simple to administer. They would be the correct metric when assessing whether employees understood the training content itself.

  • ✓

    Reduction in the number of successful phishing attacks

    Why this is correct

    Awareness programmes aim to change behaviour, so fewer successful phishing attacks demonstrates that staff actually recognise and resist real threats. This outcome metric reflects genuine risk reduction, unlike completion rates or quiz scores, which measure attendance rather than effectiveness.

  • ✗

    Percentage of employees who completed the annual training

    Why it's wrong here

    Completion counts measure attendance and administrative compliance, not whether behaviour or knowledge changed, so they cannot evidence the programme's objectives. Completion tracking is tempting because it is easy to collect and report. It would be the right metric for demonstrating training coverage or regulatory compliance rather than awareness effectiveness.

  • ✗

    Number of security incidents reported by employees

    Why it's wrong here

    Reported incident counts measure employee willingness to report, which can rise as awareness improves, but also reflect incident volume, phishing attempts and reporting culture, so they do not isolate programme effectiveness. Reporting metrics are tempting because they suggest engagement. They would be correct when evaluating the detection or reporting channel itself.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.