Courseiva

CISM Information Security Programme Practice Question

A healthcare provider is building a security awareness programme after a phishing incident exposed patient records. The CISO wants to demonstrate programme value to the board within the first year. Which approach BEST supports measuring and improving the programme?

⚠ Common exam trap

The trap here is treating a single metric, such as click rate or incident count, as proof of awareness effectiveness when attribution requires multiple complementary measures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use simulated phishing campaigns with click and report rates, combined with role-based training completion and knowledge assessments.

A credible awareness measurement approach combines behavioural evidence from phishing simulations with participation data from training completion and comprehension checks from knowledge assessments. Together these show whether staff can recognise threats and act correctly, and they reveal where reinforcement is needed. This mix produces the trend evidence boards need to judge whether the programme is reducing human risk over time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Measure the reduction in total security incidents across the organisation year over year.

    Why it's wrong here

    Total incident counts are influenced by detection capability, reporting culture, threat activity, and business changes, so they are a poor attribution measure for awareness specifically. A drop may reflect improved detection rather than better user behaviour, and a rise may reflect improved reporting. CISM cautions against attributing broad outcome metrics to a single programme without isolating its contribution.

  • ✗

    Survey employees annually on their satisfaction with security training content and delivery.

    Why it's wrong here

    Satisfaction surveys measure learner perception, not whether behaviour or knowledge changed. High satisfaction can coexist with continued susceptibility to phishing, giving the board a falsely reassuring picture. CISM expects awareness metrics to evidence behavioural change, such as reduced click rates, rather than relying on sentiment as the primary indicator of programme effectiveness.

  • ✓

    Use simulated phishing campaigns with click and report rates, combined with role-based training completion and knowledge assessments.

    Why this is correct

    Combining simulated phishing click and report rates with training completion and knowledge assessment results provides behavioural, participation, and comprehension data. This triangulation shows whether awareness activities change behaviour and where gaps persist, enabling targeted improvement. It gives the board evidence of reduced susceptibility over time, which is the outcome the programme is intended to deliver.

  • ✗

    Track the total number of phishing emails reported by staff each month and report the trend.

    Why it's wrong here

    Reporting volume can rise simply because awareness improved, making it ambiguous as a standalone success measure. It also does not indicate whether staff correctly identified malicious messages versus forwarded legitimate ones. CISM favours metrics that combine behaviour, knowledge, and outcome data, so reporting counts alone are insufficient to demonstrate programme value to the board.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.