Courseiva

CISM Information Security Programme Practice Question

A security awareness program includes phishing simulations. Which metric best measures the long-term effectiveness of the program?

⚠ Common exam trap

CISM often tests the confusion between activity metrics (e.g., number of campaigns) and outcome metrics (e.g., click rate trend), where the former measures effort and the latter measures effectiveness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Click rate trend over multiple simulation cycles

The click rate trend over multiple simulation cycles best measures long-term effectiveness because it shows whether employee behavior is improving over time. A declining trend indicates that the awareness program is successfully reducing susceptibility to phishing. Other metrics like number of campaigns or test pass rates do not directly reflect real-world behavior change.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Number of phishing simulation campaigns per year

    Why it's wrong here

    Campaign frequency measures programme activity, not whether employee susceptibility decreased, so it cannot evidence long-term effectiveness. It suits capacity and coverage planning, confirming simulations run regularly, whereas effectiveness requires tracking click and submission rates over successive campaigns.

  • ✓

    Click rate trend over multiple simulation cycles

    Why this is correct

    Click rate trend across successive simulation cycles reveals whether user behaviour genuinely improves over time, rather than reflecting a single campaign's snapshot. A sustained downward trend evidences durable learning, whereas one-off completion or report counts can be inflated by transient awareness or repeat reporting.

  • ✗

    Pass rate on phishing simulation knowledge test

    Why it's wrong here

    A knowledge test measures recall of phishing concepts, not whether staff actually apply that knowledge when a real message arrives. It suits validating comprehension immediately after training, whereas sustained behaviour change requires observing real reporting and click behaviour over time.

  • ✗

    Number of employees who report phishing emails

    Why it's wrong here

    Reporting counts rise with workforce size and reporting culture, and reporting a simulation does not demonstrate that employees resisted the lure. It suits measuring engagement and detection capability, but long-term effectiveness is shown by declining click and credential-submission rates across repeated simulations.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.