Courseiva
mediumMultiple Choice

CISA Practice Question: An organization's IT security policy requires…

An organization's IT security policy requires that all employees complete annual security awareness training. An auditor notes that completion rate is only 60%. What is the MOST effective way to monitor compliance?

⚠ Common exam trap

A common mix-up: candidates confuse knowledge testing (surprise audits) with compliance monitoring; CISA exams often test whether candidates choose automated, evidence-based monitoring over manual or subjective methods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a learning management system that tracks completions and generates reports

A Learning Management System (LMS) automates tracking of training completion, provides real-time dashboards, and generates compliance reports, which is the most effective and scalable way to monitor adherence to the annual training policy. It reduces manual effort and provides auditable evidence. This directly addresses the low completion rate by enabling continuous monitoring and follow-up.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Review training records manually each quarter

    Why it's wrong here

    Manual quarterly review samples records after the fact, so it cannot flag non-completion in time to enforce the annual policy. It is tempting because manual review suits small populations or one-off attestations, making it correct where automated learning systems are unavailable or the requirement is a point-in-time audit.

  • ✓

    Implement a learning management system that tracks completions and generates reports

    Why this is correct

    A learning management system records each employee's completion status centrally and produces auditable reports, giving continuous, verifiable evidence of the 60% shortfall. This directly satisfies the policy's need to monitor annual training compliance across the workforce.

  • ✗

    Require managers to confirm their staff's completion

    Why it's wrong here

    Manager confirmation relies on unverified self-reporting, producing no auditable evidence tied to the learning system's completion data. It is tempting because managers know their staff's schedules, making it correct where no central training platform exists and attestation is the only available compliance mechanism.

  • ✗

    Conduct surprise audits of employee knowledge

    Why it's wrong here

    Surprise knowledge audits test retention, not whether each employee completed the required training, so they cannot evidence the 60% completion gap. They are tempting because they measure real awareness, making them correct when the objective is validating training effectiveness rather than tracking completion records.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.