CISM Information Security Governance Practice Question
A security manager wants to measure the effectiveness of the security awareness program. Which metric is most relevant?
⚠ Common exam trap
CISM often tests the difference between activity metrics (e.g., number of policies updated, training completion) and effectiveness metrics (e.g., phishing click rate, incident reduction), and candidates may choose a metric that is easy to measure but does not reflect actual awareness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing simulation click rate
Phishing simulation click rate directly measures how many employees fall for simulated phishing attacks, which is a key indicator of security awareness and the effectiveness of training. A decreasing click rate over time typically indicates improved awareness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security budget variance
Why it's wrong here
Budget variance measures financial planning accuracy, not whether employees changed their security behaviour after training. Awareness effectiveness requires behavioural metrics such as phishing simulation click rates. Budget variance would be relevant when evaluating cost control of the security programme.
- ✗
Mean time to detect incidents
Why it's wrong here
Mean time to detect measures the security operations centre's monitoring and response capability, not whether staff learned from awareness training. Awareness effectiveness is evidenced by reduced phishing click rates or reporting rates. MTTD would be correct when assessing detection tooling or SOC maturity.
- ✓
Phishing simulation click rate
Why this is correct
Phishing simulation click rate directly measures whether staff apply awareness training by resisting real lures, giving behavioural evidence of programme effectiveness. It satisfies the stem's need for a metric reflecting actual security awareness rather than attendance or completion.
- ✗
Number of security policies updated
Why it's wrong here
Counting updated policies measures documentation activity, not whether staff absorbed or applied the training content. Awareness effectiveness needs behavioural evidence like phishing click-through or reporting rates. Policy counts would be correct when auditing governance documentation currency.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.