exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1396 discussion

Actual exam question from Isaca's CISA
Question #: 1396
Topic #: 1
[All CISA Questions]

Which of the following BEST indicates that the effectiveness of an organization's security awareness program has improved?

  • A. An increase in the number of staff who complete awareness training
  • B. A decrease in the number of malware outbreaks
  • C. An increase in the number of phishing emails reported by employees
  • D. A decrease in the number of information security audit findings
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Swallows
1 month, 2 weeks ago
Selected Answer: C
While it might seem counterintuitive at first glance, an increase in the number of phishing emails reported by employees often indicates that they are becoming more aware of potential security threats and are actively participating in the organization's security efforts. When employees are better educated about phishing and other social engineering attacks through security awareness training, they are more likely to recognize suspicious emails and report them to the appropriate authorities. This demonstrates that the security awareness program is effectively educating employees and empowering them to take proactive measures to protect the organization against cyber threats. On the other hand, a decrease in the number of malware outbreaks could indicate improved security measures overall but might not necessarily reflect the effectiveness of the security awareness program specifically. Therefore, an increase in reported phishing emails is typically a stronger indicator of the program's effectiveness.
upvoted 1 times
...
MJORGER
4 months, 3 weeks ago
ChatGPT: B. A decrease in the number of malware outbreaks. While all the options could be positive signs, a decrease in the number of malware outbreaks directly reflects the impact of improved security awareness among employees. It suggests that employees are becoming more vigilant and proactive in identifying and avoiding potential security threats, which is a primary objective of security awareness training programs. Therefore, a reduction in malware outbreaks is a strong indicator of the effectiveness of the security awareness program in improving overall security posture.
upvoted 1 times
MJORGER
4 months, 2 weeks ago
I am not sure about option B. Reviewing the question considering Isaca´s view probably option C (An increase in the number of phishing emails reported by employees) could be best answer.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago