CISA Governance and Management of IT Practice Question
An organization has a policy requiring all employees to complete annual information security awareness training. Which of the following is the BEST way to verify compliance with this policy?
⚠ Common exam trap
CISA often tests the distinction between verifying compliance (checking if requirements are met) and assessing effectiveness (evaluating impact or quality), so candidates may incorrectly choose phishing simulations or surveys, which measure effectiveness rather than compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review training completion records from the learning management system
The policy specifically requires employees to complete annual information security awareness training. The most direct and objective way to verify compliance is to examine the training completion records maintained by the learning management system (LMS). These records provide evidence of who has completed the training and when, directly confirming adherence to the policy. Other methods may assess effectiveness or satisfaction but do not verify completion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct phishing simulation tests
Why it's wrong here
Phishing simulations measure whether employees apply awareness knowledge, not whether they completed the mandated annual training. Simulations are the right choice for testing behavioural effectiveness or susceptibility, but policy compliance requires evidence of completion, such as training records or LMS reports.
- ✗
Survey employees about their satisfaction with training
Why it's wrong here
Satisfaction surveys capture employee opinion about training quality, not whether each employee completed the annual requirement. Surveys suit evaluating training effectiveness or content relevance, but compliance verification needs evidence of completion per employee, such as training records or system reports.
- ✗
Interview HR about training content
Why it's wrong here
Interviewing HR reveals what training is delivered and how it is tracked, not whether every employee actually completed it. HR owns content and records, so this is tempting when assessing programme design or record-keeping quality, but verifying policy compliance requires testing the population's completion status directly.
- ✓
Review training completion records from the learning management system
Why this is correct
Reviewing learning management system completion records provides direct, timestamped evidence that each employee finished the annual training, satisfying the policy's compliance verification requirement. Unlike interviews or observation, which sample behaviour, the LMS record is authoritative and auditable per employee, enabling exception reporting for those overdue.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.