CRISC Risk Response and Reporting Practice Question
A risk practitioner is evaluating the effectiveness of a security awareness program. Which TWO indicators would BEST measure whether the program is positively influencing risk culture? (Select TWO)
⚠ Common exam trap
Candidates often confuse activity-based metrics (time spent, completion rates) with outcome-based metrics (behavior change, incident reduction), which is a common CRISC pitfall when evaluating program effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase in reported phishing attempts by employees
Option C is correct because a rise in reported phishing attempts demonstrates that employees are actively recognizing and reporting suspicious emails, which reflects heightened security awareness and a stronger risk culture rather than a failure. Option E is correct because a reduction in incidents caused by human error directly shows that employee behavior has changed in a way that lowers organizational risk, which is the ultimate goal of a security awareness program. Options A and D are activity or completion metrics that only show participation, not whether awareness or behavior actually improved. Option B measures policy maintenance work, not the workforce's risk culture or the program's influence on employee behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Time spent on training per employee
Why it's wrong here
Training hours record attendance and exposure, not whether staff actually change behaviour or report risks, so they cannot evidence a shift in risk culture. They are tempting because completion metrics are easy to collect and often used for compliance reporting, where the goal is demonstrating participation rather than measuring cultural change.
- ✗
Number of security policies updated
Why it's wrong here
Counting updated policies measures documentation activity, not whether employees' attitudes and risk-aware behaviours have improved. It tempts because policy review is a genuine governance control, and in an audit or compliance context tracking policy currency is the right indicator — but it says nothing about culture.
- ✓
Increase in reported phishing attempts by employees
Why this is correct
Rising employee reports of phishing demonstrate proactive detection behaviour rather than passive compliance, directly evidencing a culture where staff treat security as their responsibility. This satisfies the stem's requirement for an indicator that the programme positively influences risk culture, since reporting suspicious emails reflects engagement and psychological safety rather than mere training completion.
- ✗
Number of employees who completed training
Why it's wrong here
Completion counts measure attendance and compliance, not whether behaviour or risk attitudes changed, so they cannot evidence culture shift. Completion tracking is correct for confirming training coverage or regulatory compliance, whereas culture requires indicators such as phishing-reporting rates or reduced incident recurrence.
- ✓
Decrease in incidents caused by human error
Why this is correct
Human-error incident counts drop only when staff actually change behaviour, so this directly evidences the awareness programme shifting risk culture rather than merely measuring attendance or completion. It reflects the stem's requirement for an indicator of positive cultural influence.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.