Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 877 discussion

Actual exam question from Isaca's CISA
Question #: 877
Topic #: 1
[All CISA Questions]

Which of the following findings should be of GREATEST concern to an IS auditor reviewing an organization’s newly implemented online security awareness program?

  • A. Employees do not receive immediate notification of results.
  • B. Only new employees are required to attend the program.
  • C. The timing for program updates has not been determined.
  • D. Metrics have not been established to assess training results.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
SRJ13
Highly Voted 1 year, 7 months ago
Option B is the correct answer. A comprehensive and effective security awareness program should be designed to educate all employees, regardless of tenure or job function, on the organization's policies, procedures, and best practices for information security. By limiting the program to only new employees, the organization is failing to address the ongoing need for all employees to remain vigilant and up-to-date on the latest threats and vulnerabilities. This leaves the organization vulnerable to potential security incidents and breaches that could result from employees who are not adequately trained and informed.
upvoted 6 times
...
Swallows
Most Recent 4 months ago
Selected Answer: D
I will change my answer to D: Participation in the program is mandatory for new hires only may present challenges in that it is mandatory only for certain employee categories, but this is not an issue directly relevant to evaluating the overall program. A security awareness program should be for all employees, but this in itself is not a primary concern in evaluating the program's effectiveness. Thus, of most concern to IS auditors is finding D, that metrics have not been established to evaluate the program's training results.
upvoted 1 times
...
RS66
4 months ago
Selected Answer: D
D. Metrics have not been established to assess training results.
upvoted 2 times
...
Swallows
8 months, 1 week ago
Selected Answer: B
Training must be provided to all employees, not just new hires, to raise organizational awareness.
upvoted 1 times
...
takuanism
9 months, 4 weeks ago
Selected Answer: B
D is important but B is more important
upvoted 3 times
...
KAP2HURUF
10 months ago
Selected Answer: D
ill go D
upvoted 2 times
...
3008
1 year, 5 months ago
Selected Answer: D
d is answer
upvoted 4 times
SuperMax
1 year, 1 month ago
D. "Metrics have not been established to assess training results." This is the most significant concern because without established metrics, it becomes challenging to assess whether the training program is achieving its goals, whether employees are improving their security awareness, and whether the program needs adjustments or updates. Metrics are essential for evaluating the program's effectiveness and making informed decisions about its future. Therefore, option D should be of the greatest concern to an IS auditor because it directly impacts the ability to measure the program's success and make data-driven improvements
upvoted 2 times
...
3008
1 year, 3 months ago
Metrics have not been established to assess training results: This is the correct answer because without metrics, it is impossible to determine the effectiveness of the training program. Metrics are essential to measuring the success of the program, identifying gaps in knowledge and behavior, and improving the program. The IS auditor would recommend that the organization establish metrics and track the results to assess the effectiveness of the training program.
upvoted 1 times
...
...
BabaP
1 year, 6 months ago
Selected Answer: B
B is a better answer
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...