Courseiva

CISA Protection of Information Assets Practice Question

An organization has implemented a security awareness training program. Which of the following metrics would BEST indicate that the program is effective?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reduction in the number of successful phishing attacks

A reduced number of successful phishing attacks indicates that employees are applying the training to recognize and avoid threats. The other metrics are useful but less direct indicators of behavioral change.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Percentage of employees who completed the training

    Why it's wrong here

    Completion percentage measures attendance, not whether behaviour or knowledge changed, so it cannot evidence effectiveness. It is tempting because it is easy to collect and report; it would be the correct metric when demonstrating programme reach or compliance with mandatory training requirements rather than actual security awareness.

  • ✗

    Average score on post-training quiz

    Why it's wrong here

    Quiz scores measure short-term recall of training content, not whether employees apply secure behaviour on the job. It is tempting because it is quantifiable and immediate; it would be the right metric when validating knowledge retention or content comprehension, not the programme's effect on real-world security outcomes.

  • ✗

    Number of reported phishing emails

    Why it's wrong here

    A rising count of reported phishing emails can reflect greater vigilance or simply more attacks, so it does not isolate programme effectiveness. It is tempting because reporting is a security-positive behaviour; it would be the correct metric when measuring detection and reporting culture, not training effectiveness itself.

  • ✓

    Reduction in the number of successful phishing attacks

    Why this is correct

    Successful phishing attacks measure actual security outcomes rather than activity. Completion rates and quiz scores reflect attendance, not behaviour change; a sustained fall in employees falling for simulated or real phishing demonstrates the training altered real-world susceptibility, which is the program's purpose.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.