Courseiva

CISA Protection of Information Assets Practice Question

Which of the following is the BEST indicator of the effectiveness of a security awareness program?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reduction in the number of successful phishing attacks.

A decrease in successful phishing attacks demonstrates behavioral change.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reduction in the number of successful phishing attacks.

    Why this is correct

    Successful phishing attacks measure actual user behaviour under real adversarial conditions, directly evidencing whether awareness training changed outcomes. Completion rates and quiz scores reflect attendance, not resistance, so a sustained reduction in successful phishing satisfies the stem's effectiveness indicator by demonstrating transferred vigilance rather than passive knowledge.

  • ✗

    Positive feedback from employees about the training.

    Why it's wrong here

    Positive feedback measures satisfaction with training delivery, not whether employees retain and apply secure behaviour; simulated phishing click rates or incident trends evidence effectiveness. It is tempting because favourable reactions are easy to collect, but they reflect perception rather than demonstrated security behaviour.

  • ✗

    Number of employees who completed the training.

    Why it's wrong here

    Completion counts measure attendance, not whether awareness improved; staff can finish modules while still falling for phishing. It tempts because completion is trivially reportable and demonstrates compliance coverage, making it the right metric when proving mandatory training rollout to an auditor.

  • ✗

    Average test scores on post-training assessments.

    Why it's wrong here

    Post-training test scores measure knowledge retention at a point in time, not whether staff behaviour or incident reporting actually changed. It tempts because assessments are easy to score and appear objective, and they would suit evaluating comprehension of specific training content rather than programme effectiveness.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.