exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 196 discussion

Actual exam question from Isaca's CISM
Question #: 196
Topic #: 1
[All CISM Questions]

Which of the following metrics provides the BEST measurement of the effectiveness of a security awareness program?

  • A. Variance of program cost to allocated budget
  • B. The number of security breaches
  • C. Mean time between incident detection and remediation
  • D. The number of reported security incidents
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Dorcy
Highly Voted 1 year, 5 months ago
Selected Answer: D
awareness increase number of reported incidents
upvoted 8 times
...
edmamol
Most Recent 1 week, 3 days ago
Selected Answer: D
The number of reported incidents shows a behaviour change in the staff due to the awareness trainings they received. These reports came in from staff members of the company which means they are wiser to phishing and other cyber attempts.
upvoted 1 times
...
Hugo1717
7 months, 3 weeks ago
Selected Answer: D
The correct answer is D. The number of reported security incidents. Explanation: The number of reported security incidents provides the best measurement of the effectiveness of a security awareness program. An effective security awareness program aims to educate employees and users about security best practices, policies, and procedures. When users are more aware of security risks and how to respond to them, they are more likely to report suspicious activities or potential security incidents.
upvoted 2 times
...
karanvp
9 months, 3 weeks ago
I think C is not a correct answer; C may be correct answer if ask to measure the effectiveness of Security Response Program. But here the question is to measure the ffectiveness of Training program
upvoted 1 times
...
wello
10 months, 1 week ago
Selected Answer: D
D for sure.
upvoted 1 times
...
richck102
10 months, 1 week ago
D. The number of reported security incidents
upvoted 1 times
...
mad68
11 months ago
Selected Answer: D
D. The number of reported security incidents. The number of reported security incidents can be a valuable metric in evaluating the effectiveness of a security awareness program. When employees are well-educated and aware of security practices, they are more likely to recognize and report potential security incidents. An increase in the number of reported incidents can indicate that employees are actively engaged in the security program and are actively identifying and reporting suspicious activities or potential threats.
upvoted 3 times
...
dark_3k03r
1 year ago
Selected Answer: D
The correct answer is D: D. The number of reported security incidents. The reason is that as more employees are aware of potential security incidents they will report more. Rationale: (A) Cost has nothing to do with the effectiveness of a program. (B) Th number can go up or down, this has less to with the awareness of the employees, but the effectiveness of the controls. (C) Meantime is great for measuring the response process but has little to do with the detection process which is the aim of a security awareness program.
upvoted 3 times
...
baranikumar_v
1 year, 3 months ago
D. number of reported incidents by employees would tend to increase after the training
upvoted 1 times
...
DelTrotter
1 year, 3 months ago
Here the question asks how to measure security awareness and awareness programme is dedicated to the entire organization -> so, cannot be that employees would analyze and solve the incident, the answer cannot be C. The answer should be D -> increased number incidents detected by employees who are better trained to detect it after awareness was conducted.
upvoted 3 times
...
D2D2
1 year, 4 months ago
Selected Answer: D
Q312 also states security awareness program effectiveness = increased reports
upvoted 3 times
...
EZPASS
1 year, 4 months ago
I agree. The answer is D.
upvoted 2 times
...
trev0r
1 year, 5 months ago
Selected Answer: C
EFFECTIVENESS is a key word in this question --> C
upvoted 1 times
wello
10 months, 1 week ago
actually SECURITY AWARENESS PROGRAM is the key words here.
upvoted 1 times
...
...
Misaki11
1 year, 6 months ago
Selected Answer: D
The mean time of reported and remediation would not be affected by awareness training
upvoted 2 times
Ziggybooboo
1 year, 5 months ago
Agreed, B or C for me
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago