Courseiva

CISM Information Security Program Practice Question

An organization's security program includes a set of metrics reported quarterly to the board. Which metric best demonstrates the effectiveness of the security awareness program?

⚠ Common exam trap

The CISM exam often tests the distinction between activity metrics (e.g., training completion) and effectiveness metrics (e.g., behavioral change), trapping candidates who confuse 'did they take the training' with 'did the training work'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reduction in phishing click-through rate

The phishing click-through rate directly measures behavioral change—the primary goal of security awareness training. A sustained reduction indicates that employees are applying training to recognize and avoid phishing attempts, which is a more valid effectiveness metric than completion rates or lagging indicators like incidents or violations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Percentage of employees who completed training

    Why it's wrong here

    Completion percentage measures attendance and delivery, not whether employees actually changed behaviour or retained the material. It is tempting because completion data is simple to collect, and it would be correct for reporting training programme coverage rather than the effectiveness of the awareness programme itself.

  • ✗

    Number of security incidents

    Why it's wrong here

    Incident counts reflect the whole threat and control landscape, so they cannot attribute change to awareness training specifically. It is tempting because incidents are easily measured and board-friendly, and this metric would be right for demonstrating overall security programme effectiveness rather than awareness.

  • ✗

    Number of policy violations

    Why it's wrong here

    Policy violation counts capture deliberate or negligent breaches across many causes, so they do not isolate awareness training's contribution. It is tempting because violations are quantifiable and trendable, and this metric would be right for measuring compliance enforcement rather than awareness effectiveness.

  • ✓

    Reduction in phishing click-through rate

    Why this is correct

    A falling phishing click-through rate directly evidences changed employee behaviour, which is the outcome a security awareness programme exists to produce. Unlike completion or attendance figures, it measures resistance to a real attack technique, giving the board quantifiable proof that awareness training reduced organisational susceptibility between quarterly reporting periods.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.