Courseiva

CISM Information Security Governance Practice Question

A security manager wants to measure the effectiveness of the security awareness program. Which metric is most relevant?

⚠ Common exam trap

CISM often tests the difference between activity metrics (e.g., number of policies updated, training completion) and effectiveness metrics (e.g., phishing click rate, incident reduction), and candidates may choose a metric that is easy to measure but does not reflect actual awareness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing simulation click rate

Phishing simulation click rate directly measures how many employees fall for simulated phishing attacks, which is a key indicator of security awareness and the effectiveness of training. A decreasing click rate over time typically indicates improved awareness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security budget variance

    Why it's wrong here

    Budget variance measures financial planning accuracy, not whether employees changed their security behaviour after training. Awareness effectiveness requires behavioural metrics such as phishing simulation click rates. Budget variance would be relevant when evaluating cost control of the security programme.

  • ✗

    Mean time to detect incidents

    Why it's wrong here

    Mean time to detect measures the security operations centre's monitoring and response capability, not whether staff learned from awareness training. Awareness effectiveness is evidenced by reduced phishing click rates or reporting rates. MTTD would be correct when assessing detection tooling or SOC maturity.

  • ✓

    Phishing simulation click rate

    Why this is correct

    Phishing simulation click rate directly measures whether staff apply awareness training by resisting real lures, giving behavioural evidence of programme effectiveness. It satisfies the stem's need for a metric reflecting actual security awareness rather than attendance or completion.

  • ✗

    Number of security policies updated

    Why it's wrong here

    Counting updated policies measures documentation activity, not whether staff absorbed or applied the training content. Awareness effectiveness needs behavioural evidence like phishing click-through or reporting rates. Policy counts would be correct when auditing governance documentation currency.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.