exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 803 discussion

Actual exam question from Isaca's CISA
Question #: 803
Topic #: 1
[All CISA Questions]

Which of the following would BEST indicate the effectiveness of a security awareness training program?

  • A. Employee satisfaction with training
  • B. Reduced unintentional violations
  • C. Results of third-party social engineering tests
  • D. Increased number of employees completing training
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
KAP2HURUF
10 months, 2 weeks ago
Selected Answer: C
The reason option C is often considered a stronger indicator is that it simulates real-world security threats and evaluates how well employees can defend against them. If employees can successfully detect and respond to social engineering attacks in these tests, it demonstrates that the training program has effectively equipped them with practical skills to protect the organization's data and systems. It's a more objective measure of readiness and effectiveness. While a reduction in unintentional violations is positive, it could be influenced by various factors beyond just the training program, making it a less direct and conclusive indicator compared to the results of third-party tests.
upvoted 1 times
...
SuperMax
1 year, 2 months ago
Selected Answer: C
The effectiveness of a security awareness training program is best indicated by: C. Results of third-party social engineering tests While all the options may provide some insights into the training program's effectiveness, the results of third-party social engineering tests are the most objective and direct measure of how well employees have internalized the training and are applying it to real-world situations. These tests simulate real-world security threats and assess whether employees are able to identify and respond to them appropriately, making it a robust indicator of the program's impact on reducing security risks. Employee satisfaction (Option A) and the number of employees completing training (Option D) can be useful metrics, but they may not necessarily correlate with improved security outcomes. Reduced unintentional violations (Option B) is a relevant metric as well, but it may not provide a comprehensive assessment of the program's effectiveness since it doesn't account for external threats that employees may face.
upvoted 2 times
...
BabaP
1 year, 6 months ago
Selected Answer: B
B is correct
upvoted 1 times
007Georgeo
1 year, 6 months ago
ChatGpt makes mistakes the right answer is C
upvoted 1 times
...
...
saado9
1 year, 6 months ago
B. Reduced unintentional violations
upvoted 2 times
007Georgeo
1 year, 6 months ago
ChatGpt makes mistakes the right answer is C
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...