CISA Protection of Information Assets Practice Question
During an audit of an organization's information security programme, the IS auditor finds that the security awareness training completion rate is 95% but phishing simulation tests show a 30% failure rate. What should the auditor recommend?
⚠ Common exam trap
CISA often tests the difference between training completion and training effectiveness, and candidates may choose to increase frequency or add disciplinary measures instead of addressing the content quality, which is the root cause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Revise the security awareness program content to focus on practical phishing recognition
The high training completion rate (95%) but high phishing failure rate (30%) indicates that the current training is not effectively translating into practical skills. Therefore, the most appropriate recommendation is to revise the content to focus on practical phishing recognition, making it more hands-on and relevant. This addresses the root cause: the training may be too theoretical or not engaging enough to change behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the frequency of phishing simulations to quarterly
Why it's wrong here
Raising simulation frequency measures detection but does not remediate the 30% click rate; the gap shows training content, not cadence, is failing. More frequent simulations suit mature programmes validating sustained vigilance, not one where nearly a third still fail.
- ✗
Disciplinary action for employees who fail phishing tests
Why it's wrong here
Discipline punishes reporting outcomes rather than closing the 30% failure gap, and can suppress phishing reporting. It is tempting where policy mandates consequences, yet the finding shows training is ineffective, so the auditor should recommend reinforcing the awareness programme instead.
- ✗
Mandate that all employees repeat the training annually
Why it's wrong here
Annual repetition leaves the 30% failure rate untouched, since completion already sits at 95% — attendance is not the deficiency. Repeating training annually suits maintaining baseline compliance, not correcting behaviour that simulations show is still unsafe.
- ✓
Revise the security awareness program content to focus on practical phishing recognition
Why this is correct
The 30% phishing failure rate exposes a gap between theoretical completion and practical detection, so revising content toward realistic phishing recognition directly targets that behavioural deficiency. Generic awareness material satisfies compliance metrics but not applied judgement; scenario-based recognition training addresses the actual control weakness the simulation revealed.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.