Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CRISC topic 1 question 473 discussion

Actual exam question from Isaca's CRISC
Question #: 473
Topic #: 1
[All CRISC Questions]

Which of the following is the BEST indicator of an effective IT security awareness program?

  • A. Decreased success rate of internal phishing tests
  • B. Number of employees that complete security training
  • C. Number of disciplinary actions issued for security violations
  • D. Decreased number of reported security incidents
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Wedeyhere2
Highly Voted 3 years, 8 months ago
I think the correct answer should be A. Decreased success rate of internal phishing tests. D is wrong because an effective security awareness program rather leads to an increase in reported security incidents since the users now know better.
upvoted 12 times
Rooks
3 years, 7 months ago
I agree. I wish someone can verify this answer.
upvoted 3 times
...
...
Staanlee
Most Recent 8 months, 1 week ago
Selected Answer: D
D. Decreased number of reported security incidents The BEST indicator of an effective IT security awareness program is "D. Decreased number of reported security incidents." A decrease in the number of reported security incidents indicates that employees are becoming more aware of security practices, recognizing potential threats, and taking appropriate actions to prevent incidents. This suggests that the awareness program is successfully influencing employees' behavior and reducing the organization's vulnerability to security breaches.
upvoted 2 times
...
mraiyan
10 months, 2 weeks ago
Selected Answer: A
Going with "A". if "D" says increase number of reported incidents then it is "D"
upvoted 1 times
...
john_boogieman
1 year, 1 month ago
Selected Answer: A
Agree 'A'.
upvoted 1 times
...
Ceecil1959
1 year, 11 months ago
Answer D should be Increased not Decreased. And BTW, phishing is done through email.
upvoted 1 times
...
Raj1510
2 years, 3 months ago
support A
upvoted 2 times
...
GLin
2 years, 7 months ago
A is Correct
upvoted 1 times
...
Tomm8125
3 years ago
Someone really needs to align the context of the questions with the manual as there are several examples in the content that state Increased number of reported security incidents is the best effective indicator of security awareness
upvoted 2 times
...
Anon530
3 years, 1 month ago
A is correct. D is in correct. There was a similar question on the CISM QAE and the answer there was an increase (NOT DECREASE) in the number of security incident report.
upvoted 2 times
...
Calvinc
3 years, 7 months ago
The answer should be A
upvoted 4 times
...
Parth9
3 years, 7 months ago
A is the correct answer
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...