CISA Protection of Information Assets Practice Question
Which of the following is the BEST indicator of the effectiveness of a security awareness program?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reduction in the number of successful phishing attacks.
A decrease in successful phishing attacks demonstrates behavioral change.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Reduction in the number of successful phishing attacks.
Why this is correct
Successful phishing attacks measure actual user behaviour under real adversarial conditions, directly evidencing whether awareness training changed outcomes. Completion rates and quiz scores reflect attendance, not resistance, so a sustained reduction in successful phishing satisfies the stem's effectiveness indicator by demonstrating transferred vigilance rather than passive knowledge.
- ✗
Positive feedback from employees about the training.
Why it's wrong here
Positive feedback measures satisfaction with training delivery, not whether employees retain and apply secure behaviour; simulated phishing click rates or incident trends evidence effectiveness. It is tempting because favourable reactions are easy to collect, but they reflect perception rather than demonstrated security behaviour.
- ✗
Number of employees who completed the training.
Why it's wrong here
Completion counts measure attendance, not whether awareness improved; staff can finish modules while still falling for phishing. It tempts because completion is trivially reportable and demonstrates compliance coverage, making it the right metric when proving mandatory training rollout to an auditor.
- ✗
Average test scores on post-training assessments.
Why it's wrong here
Post-training test scores measure knowledge retention at a point in time, not whether staff behaviour or incident reporting actually changed. It tempts because assessments are easy to score and appear objective, and they would suit evaluating comprehension of specific training content rather than programme effectiveness.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.