CISA Protection of Information Assets Practice Question
An organization has implemented a security awareness training program. Which of the following metrics would BEST indicate that the program is effective?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reduction in the number of successful phishing attacks
A reduced number of successful phishing attacks indicates that employees are applying the training to recognize and avoid threats. The other metrics are useful but less direct indicators of behavioral change.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Percentage of employees who completed the training
Why it's wrong here
Completion percentage measures attendance, not whether behaviour or knowledge changed, so it cannot evidence effectiveness. It is tempting because it is easy to collect and report; it would be the correct metric when demonstrating programme reach or compliance with mandatory training requirements rather than actual security awareness.
- ✗
Average score on post-training quiz
Why it's wrong here
Quiz scores measure short-term recall of training content, not whether employees apply secure behaviour on the job. It is tempting because it is quantifiable and immediate; it would be the right metric when validating knowledge retention or content comprehension, not the programme's effect on real-world security outcomes.
- ✗
Number of reported phishing emails
Why it's wrong here
A rising count of reported phishing emails can reflect greater vigilance or simply more attacks, so it does not isolate programme effectiveness. It is tempting because reporting is a security-positive behaviour; it would be the correct metric when measuring detection and reporting culture, not training effectiveness itself.
- ✓
Reduction in the number of successful phishing attacks
Why this is correct
Successful phishing attacks measure actual security outcomes rather than activity. Completion rates and quiz scores reflect attendance, not behaviour change; a sustained fall in employees falling for simulated or real phishing demonstrates the training altered real-world susceptibility, which is the program's purpose.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.