Courseiva
Risk Response and Reporting →mediumMultiple Select

CRISC Risk Response and Reporting Practice Question

A risk practitioner is evaluating the effectiveness of a security awareness program. Which TWO indicators would BEST measure whether the program is positively influencing risk culture? (Select TWO)

⚠ Common exam trap

Candidates often confuse activity-based metrics (time spent, completion rates) with outcome-based metrics (behavior change, incident reduction), which is a common CRISC pitfall when evaluating program effectiveness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase in reported phishing attempts by employees

Option C is correct because a rise in reported phishing attempts demonstrates that employees are actively recognizing and reporting suspicious emails, which reflects heightened security awareness and a stronger risk culture rather than a failure. Option E is correct because a reduction in incidents caused by human error directly shows that employee behavior has changed in a way that lowers organizational risk, which is the ultimate goal of a security awareness program. Options A and D are activity or completion metrics that only show participation, not whether awareness or behavior actually improved. Option B measures policy maintenance work, not the workforce's risk culture or the program's influence on employee behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Time spent on training per employee

    Why it's wrong here

    Training hours record attendance and exposure, not whether staff actually change behaviour or report risks, so they cannot evidence a shift in risk culture. They are tempting because completion metrics are easy to collect and often used for compliance reporting, where the goal is demonstrating participation rather than measuring cultural change.

  • ✗

    Number of security policies updated

    Why it's wrong here

    Counting updated policies measures documentation activity, not whether employees' attitudes and risk-aware behaviours have improved. It tempts because policy review is a genuine governance control, and in an audit or compliance context tracking policy currency is the right indicator — but it says nothing about culture.

  • ✓

    Increase in reported phishing attempts by employees

    Why this is correct

    Rising employee reports of phishing demonstrate proactive detection behaviour rather than passive compliance, directly evidencing a culture where staff treat security as their responsibility. This satisfies the stem's requirement for an indicator that the programme positively influences risk culture, since reporting suspicious emails reflects engagement and psychological safety rather than mere training completion.

  • ✗

    Number of employees who completed training

    Why it's wrong here

    Completion counts measure attendance and compliance, not whether behaviour or risk attitudes changed, so they cannot evidence culture shift. Completion tracking is correct for confirming training coverage or regulatory compliance, whereas culture requires indicators such as phishing-reporting rates or reduced incident recurrence.

  • ✓

    Decrease in incidents caused by human error

    Why this is correct

    Human-error incident counts drop only when staff actually change behaviour, so this directly evidences the awareness programme shifting risk culture rather than merely measuring attendance or completion. It reflects the stem's requirement for an indicator of positive cultural influence.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.