CISM Information Security Programme Practice Question
A security awareness program includes phishing simulations. Which metric best measures the long-term effectiveness of the program?
⚠ Common exam trap
CISM often tests the confusion between activity metrics (e.g., number of campaigns) and outcome metrics (e.g., click rate trend), where the former measures effort and the latter measures effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Click rate trend over multiple simulation cycles
The click rate trend over multiple simulation cycles best measures long-term effectiveness because it shows whether employee behavior is improving over time. A declining trend indicates that the awareness program is successfully reducing susceptibility to phishing. Other metrics like number of campaigns or test pass rates do not directly reflect real-world behavior change.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Number of phishing simulation campaigns per year
Why it's wrong here
Campaign frequency measures programme activity, not whether employee susceptibility decreased, so it cannot evidence long-term effectiveness. It suits capacity and coverage planning, confirming simulations run regularly, whereas effectiveness requires tracking click and submission rates over successive campaigns.
- ✓
Click rate trend over multiple simulation cycles
Why this is correct
Click rate trend across successive simulation cycles reveals whether user behaviour genuinely improves over time, rather than reflecting a single campaign's snapshot. A sustained downward trend evidences durable learning, whereas one-off completion or report counts can be inflated by transient awareness or repeat reporting.
- ✗
Pass rate on phishing simulation knowledge test
Why it's wrong here
A knowledge test measures recall of phishing concepts, not whether staff actually apply that knowledge when a real message arrives. It suits validating comprehension immediately after training, whereas sustained behaviour change requires observing real reporting and click behaviour over time.
- ✗
Number of employees who report phishing emails
Why it's wrong here
Reporting counts rise with workforce size and reporting culture, and reporting a simulation does not demonstrate that employees resisted the lure. It suits measuring engagement and detection capability, but long-term effectiveness is shown by declining click and credential-submission rates across repeated simulations.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.