Courseiva
hardMultiple Choice

CISA Practice Question: Is the BEST indicator that an organization's data…

Which of the following is the BEST indicator that an organization's data security governance is effective?

⚠ Common exam trap

CISA often tests the confusion between activity metrics (e.g., training percentage) and outcome-based evidence (e.g., audit findings), where the former measures effort and the latter measures effectiveness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Audit findings show compliance with data protection policies.

Audit findings that show compliance with data protection policies provide independent, objective evidence that the governance program is working as intended. Unlike metrics such as incident counts or training percentages, audit results directly assess whether controls are implemented and effective. This makes them the best indicator of governance effectiveness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Number of security incidents.

    Why it's wrong here

    Incidents can occur despite good governance.

  • ✗

    Percentage of employees trained.

    Why it's wrong here

    Training completion measures awareness activity, not whether controls actually reduce risk or meet governance objectives; a fully trained workforce can still have excessive access rights or unmonitored data flows. It is tempting because training metrics are easy to collect and report, and would be relevant when assessing a security awareness programme's coverage rather than governance effectiveness.

  • ✓

    Audit findings show compliance with data protection policies.

    Why this is correct

    Compliance with data protection policies is the strongest evidence that governance controls actually operate as intended. Audit findings provide independent verification, confirming that policies are enforced rather than merely documented, which directly satisfies the stem's requirement for an effectiveness indicator.

  • ✗

    Number of encryption keys managed.

    Why it's wrong here

    Key count is an inventory volume, not evidence that keys are rotated, segregated by data classification, or that access to them is controlled; governance effectiveness requires demonstrable policy enforcement and risk reduction. It tempts because key management is a genuine cryptographic control, and would be the right focus when auditing a key lifecycle programme's operational scope.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.