CISM Information Security Program Practice Question
An organization's security program includes a set of metrics reported quarterly to the board. Which metric best demonstrates the effectiveness of the security awareness program?
⚠ Common exam trap
The CISM exam often tests the distinction between activity metrics (e.g., training completion) and effectiveness metrics (e.g., behavioral change), trapping candidates who confuse 'did they take the training' with 'did the training work'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reduction in phishing click-through rate
The phishing click-through rate directly measures behavioral change—the primary goal of security awareness training. A sustained reduction indicates that employees are applying training to recognize and avoid phishing attempts, which is a more valid effectiveness metric than completion rates or lagging indicators like incidents or violations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Percentage of employees who completed training
Why it's wrong here
Completion percentage measures attendance and delivery, not whether employees actually changed behaviour or retained the material. It is tempting because completion data is simple to collect, and it would be correct for reporting training programme coverage rather than the effectiveness of the awareness programme itself.
- ✗
Number of security incidents
Why it's wrong here
Incident counts reflect the whole threat and control landscape, so they cannot attribute change to awareness training specifically. It is tempting because incidents are easily measured and board-friendly, and this metric would be right for demonstrating overall security programme effectiveness rather than awareness.
- ✗
Number of policy violations
Why it's wrong here
Policy violation counts capture deliberate or negligent breaches across many causes, so they do not isolate awareness training's contribution. It is tempting because violations are quantifiable and trendable, and this metric would be right for measuring compliance enforcement rather than awareness effectiveness.
- ✓
Reduction in phishing click-through rate
Why this is correct
A falling phishing click-through rate directly evidences changed employee behaviour, which is the outcome a security awareness programme exists to produce. Unlike completion or attendance figures, it measures resistance to a real attack technique, giving the board quantifiable proof that awareness training reduced organisational susceptibility between quarterly reporting periods.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.