Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 1631 discussion

Actual exam question from Isaca's CRISC
Question #: 1631
Topic #: 1
[All CRISC Questions]

Which of the following metrics would be MOST helpful to management in understanding the effectiveness of the organization’s security awareness controls?

  • A. Number of false positive alerts in a given time frame
  • B. Number of employees who have not completed training
  • C. Number of data exfiltration attempts
  • D. Number of malware incidents identified on a system
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Sara98
2 months, 2 weeks ago
Selected Answer: C
Data exfiltration attempts are a direct indicator of the effectiveness of security awareness controls. If employees are not aware of the risks of clicking on malicious links or sharing sensitive information, they are more likely to fall victim to social engineering attacks and data breaches. A high number of data exfiltration attempts suggests that security awareness controls are not working effectively. While the other options may also provide valuable information, the number of data exfiltration attempts is the most direct and relevant metric for assessing the effectiveness of security awareness controls.
upvoted 1 times
...
Abbey2
10 months, 1 week ago
Selected Answer: B
The metric that would be most helpful to management in understanding the effectiveness of the organization’s security awareness controls is: B. Number of employees who have not completed training. This metric directly reflects engagement and compliance with the security awareness program. A lower number of employees who have not completed training indicates higher participation and potentially greater awareness of security practices among staff. This metric helps management assess the reach and uptake of the security awareness program, which is crucial for its effectiveness. Effective security awareness training is a key factor in reducing security incidents, as it equips employees with the knowledge and skills to recognize and respond appropriately to security threats.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...